diff --git a/roles/configure_sysctl/files/ff.conf b/roles/configure_sysctl/files/ff.conf index 584bd67..aca9513 100644 --- a/roles/configure_sysctl/files/ff.conf +++ b/roles/configure_sysctl/files/ff.conf @@ -19,6 +19,8 @@ net.ipv6.neigh.default.gc_stale_time=3600 # decrease nf_conntrack_tcp_timeout_established - default=432000 net.netfilter.nf_conntrack_tcp_timeout_established=86400 +net.netfilter.nf_conntrack_max=65536 +net.netfilter.nf_conntrack_buckets=16384 # reboot after kernel panic kernel.panic=1