한국어English日本語简体中文繁體中文DeutschไทยTiếng ViệtРусскийPortuguês (Brasil)EspañolBahasa Indonesia

Game Lag White Paper › L5 Data center network equipment

Firewall session table full Firewall session table exhaustion

Cause ID dc-firewall · Primary owner Infra team (Network infrastructure) · Also Game team (Server development), Game team (Client development)

Open the interactive card with figures and simulations →

A firewall tracks every connection it lets through by recording it in a session table. Once the table is full, it can’t accept new connections.

Why A connection surge or an attack pushes the session count to its limit → Effect No free entry to record a new connection, so it’s refused → On screen Players trying to get in can’t connect or get infinite loading, and some existing connections disconnect too

Symptoms
Can’t connect / infinite loading, Disconnect
Factors
Packet loss
Who’s affected
Whole server
When
Right after login or maintenance, When crowds gather
Owner
Primary owner Infra team (Network infrastructure) · Also Game team (Server development), Game team (Client development)
Game team action items
Server: smooth out connection surges with a login queue, reuse connections to avoid opening short ones over and over, proactively close connections whose heartbeats have stopped (so dead connections don’t hold session table entries for long). Client: send heartbeats at no more than half the shortest idle timeout, reconnect automatically on disconnect with growing, randomized retry intervals (so everyone doesn’t pile back in at once).
Infra team action items
Enlarge the session table, clean up short-lived connections quickly (shorten the timeout for closed sessions), tell the game team whenever you shorten the idle session timeout so they can match the heartbeat interval, block attacks, alert on session table utilization.
On the graph
Hits a ceiling · Firewall session count, new connection failures
Where to look
Graph the firewall’s concurrent session count together with its session limit, and search the device log for packets dropped because a session couldn’t be created. On a Linux firewall, compare nf_conntrack_count with nf_conntrack_max and check dmesg for “nf_conntrack: table full, dropping packet”; on an AWS instance, check conntrack_allowance_exceeded in ethtool -S
Confirmed if
New connection failures rise from the moment the session count flattens at the limit, along with session creation failure logs or drop counters
Ruled out if
Session count well below the limit but connections fail: “Connection queue (listen backlog) overflow” or the login server. Only idle connections drop: “Cloud security group connection tracking expiry”
Check with
Infra tools (no game code needed)

Sources

  1. Netfilter Conntrack Sysfs variables Linux kernel
    Maximum entries in the connection tracking table (nf_conntrack_max), how long closing connections are kept (TIME_WAIT and FIN_WAIT default 120 seconds), established TCP default 5 days, current entry count (nf_conntrack_count)
  2. Amazon EC2 security group connection tracking AWS
    Once an instance exceeds the number of connections it can track, packets for new connections are dropped; idle connections can exhaust the tracking table
  3. Infrastructure layer attacks AWS
    Attacks such as SYN floods tie up server, firewall, and load balancer resources
  4. net/netfilter/nf_conntrack_core.c (Linux v6.12) Linux kernel
    When the connection tracking table is full, the kernel logs “nf_conntrack: table full, dropping packet” and drops packets for new connections
  5. Monitor network performance for ENA settings on your EC2 instance AWS
    conntrack_allowance_exceeded: number of packets dropped because the instance exceeded its connection tracking allowance, visible with ethtool -S

See also

Same layer: L5 Data center network equipment

Same symptom (Can’t connect / infinite loading), other layers

View the interactive card with figures and simulations