A firewall tracks every connection it lets through by recording it in a session table. Once the table is full, it can’t accept new connections.
Why A connection surge or an attack pushes the session count to its limit → Effect No free entry to record a new connection, so it’s refused → On screen Players trying to get in can’t connect or get infinite loading, and some existing connections disconnect too
Right after login or maintenance, When crowds gather
Owner
Primary owner Infra team (Network infrastructure) · Also Game team (Server development), Game team (Client development)
Game team action items
Server: smooth out connection surges with a login queue, reuse connections to avoid opening short ones over and over, proactively close connections whose heartbeats have stopped (so dead connections don’t hold session table entries for long). Client: send heartbeats at no more than half the shortest idle timeout, reconnect automatically on disconnect with growing, randomized retry intervals (so everyone doesn’t pile back in at once).
Infra team action items
Enlarge the session table, clean up short-lived connections quickly (shorten the timeout for closed sessions), tell the game team whenever you shorten the idle session timeout so they can match the heartbeat interval, block attacks, alert on session table utilization.
On the graph
Hits a ceiling · Firewall session count, new connection failures
Where to look
Graph the firewall’s concurrent session count together with its session limit, and search the device log for packets dropped because a session couldn’t be created. On a Linux firewall, compare nf_conntrack_count with nf_conntrack_max and check dmesg for “nf_conntrack: table full, dropping packet”; on an AWS instance, check conntrack_allowance_exceeded in ethtool -S
Confirmed if
New connection failures rise from the moment the session count flattens at the limit, along with session creation failure logs or drop counters
Ruled out if
Session count well below the limit but connections fail: “Connection queue (listen backlog) overflow” or the login server. Only idle connections drop: “Cloud security group connection tracking expiry”
Check with
Infra tools (no game code needed)
Sources
Netfilter Conntrack Sysfs variablesLinux kernel Maximum entries in the connection tracking table (nf_conntrack_max), how long closing connections are kept (TIME_WAIT and FIN_WAIT default 120 seconds), established TCP default 5 days, current entry count (nf_conntrack_count)
Amazon EC2 security group connection trackingAWS Once an instance exceeds the number of connections it can track, packets for new connections are dropped; idle connections can exhaust the tracking table
net/netfilter/nf_conntrack_core.c (Linux v6.12)Linux kernel When the connection tracking table is full, the kernel logs “nf_conntrack: table full, dropping packet” and drops packets for new connections