Question
Should you raise the file‑descriptor limit or enable TCP_TW_REUSE to prevent connection‑pool exhaustion on NAT‑exposed hosts?
Nia Finch
0 reputation · 02 Nov 2020, 20:37 UTC
144.2K views0
Goal
Select a mitigation that reliably prevents intermittent connection‑pool exhaustion on Unix hosts handling high‑churn outbound traffic.
Constraints
- TCP_TW_REUSE is unsafe on systems that act as NAT routers or that rely on TIME_WAIT for duplicate‑packet suppression.
- Raising the per‑process file‑descriptor limit can hide application‑level leaks and requires the kernel global
fs.file-maxto be increased accordingly.
Open questions
- Under what workload patterns does a modest limit increase alone eliminate exhaustion?
- When is it safe to enable TCP_TW_REUSE together with a higher limit on mixed NAT and non‑NAT services?
- What verification steps confirm that the chosen approach does not mask underlying connection leaks?