ã½ã±ããéä¿¡ possible SYN flooding on port 443. Sending cookies. ããã°ã«åºã¦ããLinux ã¯ããã« ã¤ã³ã¿ã¼ãããã«å ¬éãã¦ãããã¼ã ãã¼ã¸ãçªç¶é²è¦§ã§ããªããªãã¾ããããµã¼ãã§ã¯ãã¼ãã¢ãã¬ã¼ã¸ãä½ããè² è·ã¯ããã£ã¦ããªãããã§ãããä»åã®è¨äºã§ã¯ãã®ç¶æ³ä¸ã§ã®ããã«ããã¯ã®ç¢ºèªï¼å¯¾å¿æ¹æ³ã«ã¤ãã¦ç°¡åã«ã¾ã¨ãã¦ã¿ã¾ããã ç°å¢ CentOS6 Apache åè https://qastack.jp/server/294209/possible-syn-flooding-in-log-despite-low-number-of-syn-recv-connections https://github.com/hiboma/hiboma/blob/master/kernel/net/net-backlog.md https://qiit
TCP ã®ééæ§ æçµæ´æ°2004-12-26T00:00:00+09:00 ãã®è¨äºã®URIåç §https://www.7key.jp/nw/tcpip/tcp/tcp2.html#transp TCPã®ãã©ã³ã¹ãã¼ã層ã¨ãã¦ã®å½¹å²ã¨ãã¦å¤§åãªã®ã¯éä¿¡ã®ä¿¡é ¼æ§ã確ä¿ãããã¨ã§ããä»åã¯ã³ãã¯ã·ã§ã³ã®ä¸ã§ããã®ä¿¡é ¼æ§ã確ä¿ããããã®ããªãã¨ãªãé¨åã«ã¤ãã¦èª¬æãè¡ãã¾ãããã®ããªãã¨ãªãæ©è½ã¯å¤§ããåãã¦ç¢ºèªå¿çã¨åéå¶å¾¡ã®äºã¤ããæãç«ã¡ã¾ãã確èªå¿çã¯ããã¼ã¿ãããã¾ã§åãåãã¾ããããã¨ããã¥ã¡ããã¤æ©è½ã®ãã¨ãè¨ããåéå¶å¾¡ã¯ç¸æã«ãã¼ã¿ãå±ããªãã£ããã¨ãæ¤ç¥ããéããã«å±ããªãã£ããã¼ã¿ãç¸æã«åéããæ©è½ã®ãã¨ãè¨ãã¾ãããããã®æ©è½ã«ããããã¼ã«ã«ã®ã¢ããªã±ã¼ã·ã§ã³éããéä¿¡ãã¦ããã®ã¨å¤ãããªãç°å¢ããããã¯ã¼ã¯çµç±ã§ãå®ç¾ãããã¨ãã§ããã®ã§ããããããã³ãã¯ã·ã§ã³ã®æ§
æ¬é¨é·ãå¯æ¬é¨é·ãããã°ã©ãã³ã°ãï¼ãã¾ã«ï¼ãããã¨ã§æåãªãµã¤ãã¦ãºã®éç¨æ¬é¨é·ãå±±æ¬æ³°å®ã§ãã æåãããªãããããã¾ããããããã°ã«æ¸ããã®ã§æåã«ãªãã¨ãããã¨ã§ãäºæ¿ãã ããã ä»åã¯ãå æ¥çºçãã yrmcds ã«èµ·å ããé害ã®åå ã¨å¯¾çã解説ãã¾ãã yrmcds ã¨ããã®ã¯ããµã¤ãã¦ãºãéçºãã¦ãã memcached äºæã®ãã¼ããªã¥ã¼ã¹ãã¬ã¼ã¸ã§ãã åé¡ã®ç解ã®ãããã¾ã TCP éä¿¡ã§ãéä¿¡å ã®ç¸æã®é害ã«ã©ã対å¿ããã解説ãã¾ãã ãã¼ã¿ã®éä¿¡ä¸ã«ç¸æãè½ã¡ãã±ã¼ã¹ ãã®ã±ã¼ã¹ã¯ããã«äºã¤ã«åããã¾ãã ç¸æã® OS ã¯çãã¦ããããéä¿¡ãã¦ããããã°ã©ã ãè½ã¡ãã±ã¼ã¹ ç¸æã® OS ãã¨ï¼ãããã¯ãããã¯ã¼ã¯ãã¨ï¼è½ã¡ãã±ã¼ã¹ 1 㨠2 ã®éãã¯ãåè ã®å ´å RST ãã±ãããè¿ã£ã¦ããã®ã«å¯¾ãã¦ãå¾è ã§ã¯ãªã«ãè¿ã£ã¦ããªãç¹ã§ããå¾è ã®å ´åãack ãããªã
ã¤ã³ã¿ã¼ããããæµãããã©ãã£ãã¯ã®ã»ã¨ãã©ãTCP(Trasmission Control Protocol)ã«ãããã®ã§ãã TCPã¯ãå ¨ã¦ã®ãã¼ã¿ãæ£ããç¸æã«ä¼ãããã¨ãä¿è¨¼ããããå質ã®é«ããã¼ã¿éä¿¡ãå®ç¾ã§ãã¾ãã ã¾ããã©ã®ãã±ãããåãåããªãã¦ãã©ããåãåããããªã©ãããããèããªãã¦ãè¯ãã®ã§ãããã°ã©ã ãæ¸ãã®ãç°¡åã§ãã ã§ã¯ãä½æ ãããããRTPã¨ãããã®ãå¿ è¦ã ã£ãã®ã§ããããï¼ ããã§ã¯ãã¾ãæåã«ä½æ RTPã¯TCPã§ã¯ãªããUDPã®ä¸ã«åå¨ãã¦ããã®ãã説æãããã¨æãã¾ãã ï¼ãã¡ãããTCPã®ä¸ã«ä½ããã¨ã¯RTPã®è¦ç´ä¸ã¯å¯è½ã§ãããç¾å®çã«ã¯UDPã®ä¸ã§ããå®è£ ããªãã¨æãã¾ããï¼ ãã®å¾ãä½æ ãUDPã®ä¸ã«å ±éã®RTPã¨ãããã®ãæ§ç¯ããã®ãã説æãããã¨æãã¾ãã RTPã¯ãååã«ãããéããããªã¢ã«ã¿ã¤ã ããªãã¼ã¿ã転éããããã®ãããã³ã«ã§ã
ããåå¹´ããããã«Dockerã§microservicesãªãµã¼ãã¹ãéç¨ãã¦ããã§ãããã¤ãã¤ãããã©ã¼ãã³ã¹ãåºãåãã¦ããªããªã¨ããé¢ãããã¾ãã¦ãä»åDockerãã¹ãã®TCPã«ã¼ãã«ãã©ã¡ã¼ã¿ãææ¬çã«è¦ç´ãã¾ããã ããããåçã«çç¶ãæ¹åãã¦ãã¤ã³ã¹ã¿ã³ã¹æ°ãåæ¸ã§ããä¸ã«å®å®ãã¦ã¡ã·ã¦ãç¶æ ã«ãªã£ãã®ã§ç´¹ä»ãã¾ããå®éå¹æããã£ãã®ã§ãã¥ã¼ãã³ã°ãã¤ã³ãã¨ãã¦ã¯ããç¨åº¦æ£è§£ã§ãã£ãã¨èãã¦ãã¾ããããã¡ããæ±ã£ã¦ãã¢ããªã±ã¼ã·ã§ã³ã®ç¹æ§ã«ãããã¯ããªã®ã§ä¸ã¤ã®ã±ã¼ã¹ã¹ã¿ãã£ã§ãããã¨ããäºæ¿é ããã°ã¨ã åæ ã¾ãã¯ä»åã®ã話ã®åæãããããªç°å¢ã§ãã EC2 c3.xlarge ãã¹ãã¯Ubuntuï¼EC2 Optimized AMIã¯æªä½¿ç¨ï¼ Docker 1.11.2 MySQLï¼HAProxyçµç±ï¼ãRedisã¸ã®ãã¼ã¿ã¹ãã¢ã®éä¿¡ãåmicroservicesã¸ã®
ååã®ç¶ãã ãã±ããèªä½ãé¶ããã«å¦çã«å ¥ã£ãå¾ã«SYNãè½ã¨ãã®ã¯ä»¥ä¸3ãã¿ã¼ã³ã syncookieç¡å¹æã«synã®backlog(tcp_max_syn_backlog)ã溢ãã¦ãã listenã®backlogã溢ãã¦ãã(3way-handshakeå®äºå¾ã®acceptå¾ ã¡æ¥ç¶) net.ipv4.tcp_tw_recycleã®å¶éã«æµè§¦ ã§ãä»ååé¡ã«ãªã£ã¦ããã®ã¯æå¾ã®tcp_tw_recycleã¸ã®æµè§¦ã ã£ãã ç¾è±¡ã¨ãã¦çºçãããã®ã¯ã以ä¸ã®æ¡ä»¶ããã¹ã¦æºããå ´å ãµã¼ãå´ã§net.ipv4.tcp_tw_recycleãæå¹ TCPã¿ã¤ã ã¹ã¿ã³ããªãã·ã§ã³ãä½¿ç¨ åä¸IPããã®æ¥ç¶ã§ã»ãã·ã§ã³ãè·¨ãã¨ã»ãããããTCPã¿ã¤ã ã¹ã¿ã³ãã®å¤ãæ»ãå ´åããã æå¾ã®æ¡ä»¶ãå¾®å¦ã ããTCPã¿ã¤ã ã¹ã¿ã³ãã®å¤ã¨ãã¦ã»ãããããå¤ã¯èµ·åæã èµ·ç®æã«ãã¦ãããã¨å®è£ ã«ãã£ã¦åæå¤
ãã®ãã¡ãã¢ããªã±ã¼ã·ã§ã³ãä½ãããã«æ°ã«ããå¿ è¦ãããã®ã¯ãã©ã³ã¹ãã¼ã層ãããä¸ã®ã¬ã¤ã¤ã¼ã ãã§ãã å®éã®ã¤ã³ã¿ã¼ãããéä¿¡ã§ã¯ãã±ã¼ãã«ãç¡ç·ãéãã¦IPãã±ããã®å½¢ã§ãã¼ã¿ãããåãããã¾ããã ã¢ããªã±ã¼ã·ã§ã³ã§ç´æ¥IPãã±ãããä½ã£ããããããã§ã¯ããã¾ããã HTTPãTCPã®ã¬ãã«ã§æ±ºãããã¦ããã«ã¼ã«ã«å¾ã£ã¦éä¿¡ãããã°ãããããä¸ã®ã¬ã¤ã¤ã¼ã§å¿ è¦ã«ãªã詳細ãæ°ã«ãããã¨ãªãã ãããã¯ã¼ã¯ã®åããå´ã«ããã¢ããªã±ã¼ã·ã§ã³ã¨ããåããã§ããããã§ãã Goè¨èªã§ã¯ãHTTPãTCPãUDPã«ã¤ãã¦çµã¿è¾¼ã¿ã®æ©è½ãæä¾ããã¦ãã¾ã1ã å®ç¨çãªã¢ããªã±ã¼ã·ã§ã³ã§ã¯ããããã®æ©è½ã使ã£ã¦ãèªåã®ã¢ããªã±ã¼ã·ã§ã³ã«å¿ è¦ãªãããã³ã«ãå®è£ ãã¦ãããã¨ã«ãªãã¾ãã HTTPã¨ãã®ä¸ã®ãããã³ã«ãã¡ ä»åã®è¨äºã®ç®æ¨ã¯ããããã¯ã¼ã¯ãæ±ãããã°ã©ã ã«ã¨ã£ã¦ä½ã¬ãã«ãªã½ã±ãããGoè¨
QUICï¼Quick UDP Internet Connectionsï¼ãããã³ã«ã¯ãTCPã§ã¯ãªãUDPããã¼ã¹ã¨ãã¦éçºããããå ¨ãæ°ããWebåãã®ãããã³ã«ã§ãã ï¼åè«ã§ï¼ TCP/2 ã¨å¼ã¶äººã¾ã§ãã¾ãã ç§ãQUICã«ã¤ãã¦ç¥ã£ãã®ã¯æ°é±éåã®ãã¨ã§ãã SysCast Podcastã®curlã¨libcurlã«ã¤ãã¦ã®ã¨ãã½ã¼ã ãèãã¦ããæã§ããã QUICãããã³ã«ã®æ¬å½ã«é¢ç½ãç¹ã¯ãUDPã¸ã®ç§»è¡ã¨ããã¨ããã ã¨æãã¾ãã ç¾å¨ãWebã®ä¼éãããã³ã«ã¯ãä¿¡é ¼æ§ã確ä¿ãããããTCPä¸ã«æ§ç¯ããã¦ãã¾ãããã®TCPæ¥ç¶ãéå§ããããã«ã¯ã 3wayãã³ãã·ã§ã¤ã¯ ãè¡ããã¦ãã¾ããã¤ã¾ãããã¯ãæ¥ç¶ãéå§ãããã³ã«ã©ã¦ã³ãããªãã ï¼ãããã¯ã¼ã¯ãã±ããã®å¾å¾©ï¼ ã追å ãããã¨ãããã¨ã§ãããæ°ããªæ¥ç¶å ã«å¯¾ãå¤§å¹ ãªé 延ãçãããã¦ããã®ã§ãã ï¼åºå ¸ï¼ UDPãä»
TCP ã®ãã¥ã¼ãã³ã°ã»ãã©ã¡ã¼ã¿ æ¥ç¶ç¢ºç«é¢ä¿ã®ãã¥ã¼ãã³ã°ã»ãã©ã¡ã¼ã¿ TCP ã®ãã¥ã¼ãã³ã°ã»ãã©ã¡ã¼ã¿ TCP ã®ãã¥ã¼ãã³ã°ã»ãã©ã¡ã¼ã¿ã¯ã以ä¸ã®ã³ãã³ãã§åå¾ã§ãã¾ãã ãªãã以ä¸ã¯ Linux ã®ãã®ã§ãã >cat /proc/sys/net/ipv4/tcp_retrans_collapse 1 >cat /proc/sys/net/ipv4/tcp_keepalive_probes 9 >cat /proc/sys/net/ipv4/tcp_keepalive_time 10800 >cat /proc/sys/net/ipv4/tcp_syn_retries 10 >cat /proc/sys/net/ipv4/tcp_sack 1 >cat /proc/sys/net/ipv4/tcp_timestamps 1 >cat /proc/sys/net/ipv4/tcp
/procã«ããLinuxãã¥ã¼ãã³ã° ï¼»å¾ç·¨ï¼½ ï½ /proc/sysã®ä¸»è¦ãã©ã¡ã¼ã¿ç¾¤ç·è§£èª¬ ï½ é ç° èå¹³ 2002/12/17 /proc/sys/fsãã£ã¬ã¯ã㪠/proc/sys/fsã«ã¯ããã¡ã¤ã«ã·ã¹ãã é¢é£ã®ãã¥ã¼ãã³ã°ãã©ã¡ã¼ã¿ãéãããã¦ãã¾ãã file-max ã·ã¹ãã ä¸ã®ãªã¼ãã³ãã¡ã¤ã«ç®¡çãã¼ã¿ã®æ大æ°ãæå®ã§ãã¾ãã file-nr file-nrå ã®ãã©ã¡ã¼ã¿ã¯ããããããªã¼ãã³ããã¦ãããã¡ã¤ã«æ°ã空ããã¡ã¤ã«ç®¡çãã¼ã¿ã®æ°ãã·ã¹ãã ä¸ã®ãªã¼ãã³ãã¡ã¤ã«ç®¡çãã¼ã¿ã®æ大æ°ï¼file-maxã¨åãï¼ã示ãã¾ãã ãã¡ã¤ã«ã®ã¯ãã¼ãºæã«ã¯ã使ã£ã¦ãããã¡ã¤ã«ç®¡çãã¼ã¿ãå³åº§ã«è§£æ¾ããã®ã§ã¯ãªãããã£ããï¼æ¬¡ã®æ©ä¼ã«ä½¿ããããã«ï¼åãç½®ãã¾ãããã®åãç½®ããã¦ãã管çãã¼ã¿ã®æ°ãã2çªç®ã®æ°å¤ã¨ãªãã¾ãã inode-stateãinode-nr inode-
listenã®ããã¯ãã°ãæå®ã§ããªã - æ®çºæ§ã®ã¡ã¢ã®ç¶ã http://www.linux.or.jp/JM/html/LDP_man-pages/man2/listen.2.html int listen(int sockfd, int backlog); backlogã§ããã¯ãã°ã®æ°ï¼accept()å¾ ã¡ã®æ¥ç¶ã®ãã¥ã¼ã®æ°ãæå®ã§ããã ã¨ãããã¨ã«ãªã£ã¦ãããã©ãå®éã¯ãã¥ã¼ã®æ°ããã¾ãå¶éã§ããªãã£ã½ãã ã«ã¼ãã«å´ã®è¨å®ã # cat /proc/sys/net/ipv4/tcp_syncookies 0 # cat /proc/sys/net/ipv4/tcp_max_syn_backlog 1ããã°ã©ã å´ã result = listen( sd, 1 );ã¨ãã¦å¶éããã¦ãã¦ããå®éã«ã¯ã»ãã·ã§ã³ã確ç«ãã¦ãã¾ãã tcp 0 0 172.16.1.4:5000 1
ããã§ã¯ï¼Webã¯ã©ã¤ã¢ã³ãããã®æ¥ç¶æ°ã®å¶å¾¡ã¨ï¼ãªã¯ã¨ã¹ãå¦çã¹ã¬ããæ°ã®å¶å¾¡ã«ã¤ãã¦èª¬æãã¾ãã ã¤ã³ããã»ã¹HTTPãµã¼ãã§ã¯ï¼ä¸åº¦ã«æ¥ç¶ã§ããWebã¯ã©ã¤ã¢ã³ãã®æ°ãè¨å®ãããã¨ã§ï¼ã¤ã³ããã»ã¹HTTPãµã¼ãã§ä½æãããªã¯ã¨ã¹ãå¦çã¹ã¬ããæ°ãå¶å¾¡ã§ãã¾ããã¾ãï¼å¦çãå®è¡ãã¦ããªããªã¯ã¨ã¹ãå¦çã¹ã¬ãããäºåã¹ã¬ããã¨ãã¦ä¸å®æ°ãã¼ã«ãã¦ãããã¨ã§ï¼ãªã¯ã¨ã¹ãå¦çã¹ã¬ããã®è¿½å ã»åé¤ã«æããå¦çãæå°éã«æãããã¾ãã ãã®ããã«ï¼Webã¯ã©ã¤ã¢ã³ãããã®æ¥ç¶æ°ã¨ãªã¯ã¨ã¹ãå¦çã¹ã¬ããæ°ãå¶å¾¡ãã¦ï¼ãªã¯ã¨ã¹ãå¦çã¹ã¬ããæ°ãæé©åãããã¨ã«ãã£ã¦ï¼J2EEãµã¼ãã®è² è·ãä¸å®ã«æãï¼å®å®ããé«ãã¹ã«ã¼ããããç¶æã§ãã¾ãã Webã¯ã©ã¤ã¢ã³ãããã®æ¥ç¶æ°ã®å¶å¾¡ã¨ãªã¯ã¨ã¹ãå¦çã¹ã¬ããæ°ã®å¶å¾¡ã«ã¤ãã¦èª¬æãã¾ãã ï¼ãã®é ã®æ§æï¼ (1)ãWebã¯ã©ã¤ã¢ã³ãããã®æ¥ç¶æ°ã®å¶å¾¡ (2)
å°ãã ãçªã£è¾¼ãã 話ã ï¼ææ§ãã¯äººéã®è³å è£å®ã«å§ããã¨ãã¦ï½¥ï½¥ï½¥ãï¼ Linuxã«ã¯TCPã®3Wayãã³ãã·ã§ã¤ã¯ï¼å³ã¡ãSYN,SYN/SCK,ACKï¼ç¶æ ä¿æã«é¢é£ãã¦ã 次ã®ãããªãã©ã¡ã¼ã¿ãæã£ã¦ããã net.ipv4.tcp_max_syn_backlog=1024 ä½ããï¼ã£ã¦äººã¯ # sysctl -a | grep tcp çã®ã³ãã³ãã§æ¢ãã¾ãã # sysctl -a | grep backlogï¼ãããããã¤ãºãç¡ãããã¦é¢ç½ãï½(ry ããã¯ããLinuxãSYNãåä¿¡ããSYN/ACKã§å¿çããç¶æ ãããã¤ä¿æããããã¨ãããã®ã é¾å¤ãè¶ ããã¨ãLinuxã¯æ°è¦ã«æ¥ç¶ãããã¨ãããã¹ãã®ãªã¯ã¨ã¹ãï¼SYNï¼ãç¡è¦ããã æè¿ã®Linuxããæè¿ã®ãã¼ãã¦ã§ã¢ã«ã¨ããããã¤ã³ã¹ãã¼ã«ããã¨ã åæå¤ã¯ä¸è¨ã®ãããª1024ã¨ãè¨ãæ°å¤ã«ãªã£ã¦ããã¨æãã å©ç¨
Interstage Application Server Webãµã¼ãéç¨ã¬ã¤ã (Interstage HTTP Serverç·¨) åå ListenBacklog å½¢å¼ ListenBacklog æ¥ç¶å¾ ã¡ãã¥ã¼ã®æå¤§æ° ListenBacklog æ¥ç¶å¾ ã¡ãã¥ã¼ã®å ç®æ° æ©è½æ¦è¦ æ¥ç¶å¾ ã¡ãã¥ã¼ã®æ大æ°ãè¨å®ãã¾ããæ大æ°ã«ã¯ã1ãã2147483647ã¾ã§ãæå®ã§ãã¾ãã æ¬ãã£ã¬ã¯ãã£ãã®è¨å®å¤ã¯ãMaxClientsãã£ã¬ã¯ãã£ãã§è¨å®ããã¯ã©ã¤ã¢ã³ãã®åææ¥ç¶æ°ãããå¤ãã®ã¢ã¯ã»ã¹è¦æ±ããã£ãå ´åã«ãSolaris OEã·ã¹ãã å ã«ãã¥ã¼ã¤ã³ã°ãããæ°ã¨ãã¦æå¹ã¨ãªãã¾ãã ãã ããæ¬ãã£ã¬ã¯ãã£ãã®è¨å®å¤ãSolaris OEã·ã¹ãã ã«è¨å®ããã¦ããå¾ æ©ä¸TCPã³ãã¯ã·ã§ã³ã®æ大å¤ï¼tcp_conn_req_max_qï¼ããã大ããå ´åã¯ãå¾ æ©ä¸TCPã³ãã¯ã·ã§ã³ã®æ大å¤
linuxãµã¼ãã®OSå ¨ä½ã«å¹ãã«ã¼ãã«ãã©ã¡ã¼ã¿ã®ãã¥ã¼ãã³ã°ç®æ㨠ãã®è¨å®å¤ãã¾ããã®çç±ãã¾ã¨ãã¦ããã ããã¾ã§èªåã®ç°å¢ã§ã¯ãããããã¨ããã ãã§ããã æä¾ãããµã¼ãã¹ãã¨ã«æ¤è¨ãå¿ è¦ã§ããã ã©ããã©ãå¤æ´ããã®ããã¾ãã¯å¤ããªãã®ãããã®å¤æææã«ã¯ãªãã ããã â»ã¦ã¼ã¶åä½ã§ã·ã¹ãã ãªã½ã¼ã¹ã«å¶éããããå ´åããã¡ããåç §ãã¦ã»ããã 以ä¸ã¯/etc/sysctl.conf ã§è¨å®ãããã®ã¨ããã â 大è¦æ¨¡ãµã¤ãç¨ãã¥ã¼ãã³ã° kernel.pid_max åä½ï¼pidã®æå¤§æ° è¨å®å¤ï¼131072 çç±ï¼pidãæ¯æ¸ãããªã vm.max_map_count åä½ï¼mmapãmallocæã«ã¡ã¢ãªãä»®æ³ç©ºéã«ãããã³ã°ã§ããæ大ãã¼ã¸æ° è¨å®å¤ï¼300000 çç±ï¼ãããã³ã°ã§ããªããªãäºæ ãé²ã net.core.somaxconn åä½ï¼æ¥ç¶(ã½ã±ãã)ãã¥ã¼ã®
çµè« tcp_syncookies = 0 ã®å ´å tcp_max_syn_backlog ã® 75% ãè¶ ãã half openãªã³ãã¯ã·ã§ã³è¦æ±ãæ¥ãå ´åãdropããã(TCP: drop open request from [IP]/[PORT]) somaxconn 㨠tcp_max_syn_backlogã®å°ããã»ãã®å¤ããä»è¿ã®2ã®ç´¯ä¹ã®å¤ã«åãä¸ããæ°å¤ãè¶ ããã¨ãdrop (TCP: Possible SYN flooding on port [PORT]. Dropping request.) tcp_syncookies = 1 ã®å ´å somaxconn 㨠tcp_max_syn_backlogã®å°ããã»ãã®å¤ããä»è¿ã®2ã®ç´¯ä¹ã®å¤ã«åãä¸ããæ°å¤ãè¶ ããã¨ãcookieéä¿¡ (TCP: Possible SYN flooding on port [PORT]
æ¦è¦ â memcachedã®tcp_backlogã®ããã©ã«ãå¤ã¯1024ã§ãstats settingsã«ã1024ã¨è¡¨ç¤ºããã¦ããã®ã§ããã stats settings ... STAT tcp_backlog 1024 ... ENDâ net.core.somaxconnãããã©ã«ãå¤ã®ã¾ã¾ã ã¨128ã«åãè©°ãããã¦ãã¾ãã # cat /proc/sys/net/core/somaxconn 128è² è·ãé«ããµã¼ãã¼ã§ã¯æ¥ç¶è¦æ±ãåããã¼ãã¦ãã¾ããã¨ãããããã§ãã ãã®net.core.somaxconnãMemcacheãMySQLãªã©ãé«è² è·æã«å¤ãã®æ¥ç¶è¦æ±ãåãä»ãããµã¼ãã¼ã§ã¯ãã¥ã¼ãã³ã°ãå¿ è¦ãªã«ã¼ãã«ãã©ã¡ã¼ã¿ã®ããã§ãããã£ããã©ãããå¤ãªã®ãã調ã¹ã¦ã¿ã¾ããã net.core.somaxconnã¨ã¯ TCPã½ã±ããã¯listen()é¢æ°ã®ç¬¬äºå¼æ° ba
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}