When the connection tracking (conntrack) table, where the Linux firewall records every connection, reaches its limit, new packets are dropped.
Why Connection surges and repeated short-lived connections pile up connection entries → Effect The table fills up, and new connections and some packets are dropped → On screen Can’t connect, and teleporting from unexplained packet loss
Right after login or maintenance, When crowds gather
Owner
Primary owner Infra team (Server infrastructure) · Also Game team (Server development), Game team (Client development)
Game team action items
Server: cut down short-lived connections (reuse connections for server-to-server calls). Client: when a connection fails or drops, retry with growing, randomized intervals.
Infra team action items
Raise the table size (nf_conntrack_max), exclude game ports from tracking (NOTRACK in the raw table), alert on usage.
Ballpark numbers
The default limit is about 60,000 to 260,000 entries depending on server memory. When it overflows, the kernel log shows “nf_conntrack: table full, dropping packet”.
On the graph
Hits a ceiling · conntrack entry count (nf_conntrack_count)
Where to look
net.netfilter.nf_conntrack_count (current entries) from sysctl on the same graph as nf_conntrack_max, and “nf_conntrack: table full, dropping packet” in dmesg
Confirmed if
nf_conntrack_count flattens at max, and from that moment the kernel log shows table full
Ruled out if
Entry count well below max: not this cause. For the AWS instance’s own connection tracking limit, check conntrack_allowance_exceeded (see “Cloud PPS limit exceeded”)
Check with
Infra tools (no game code needed)
Sources
Netfilter Conntrack Sysfs variablesLinux kernel nf_conntrack_max defaults to the number of hash buckets (nf_conntrack_buckets), which is set by memory size
net/netfilter/nf_conntrack_core.c (Linux v6.12)Linux kernel Default size is 65,536 with more than 1 GB of memory and 262,144 with more than 4 GB (64-bit); when full, it logs “nf_conntrack: table full, dropping packet” and drops