    Time_Wait problem

    hello i have problem in time_wait it's very high

    netstat -an|grep ":80"|awk '/tcp/ {print $6}'|sort| uniq -c
    15 FIN_WAIT1
    2 FIN_WAIT2
    1 LAST_ACK
    2 LISTEN
    10 SYN_RECV
    1026 TIME_WAIT

    i hope any one solve this problem


    netstat -ntu | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -n
    Any of the IP's have a lot of connections?
    Cody R.
    i have more ips have more connection but the ips change not static

    Well I have something similar. Is there any reason to worry? All my sites are responsive and server is doing well

    It seems the reason that it happens is because TIME_WAIT is the state before CLOSED in TCP. TCP is a Session protocol. It ensures that packets get delivered. Only two packets in the entire session are not reliable: SYN and FIN+ACK. Without boring you with details, here's a much better description:

    If you want to decrease your timeout to increase your connection rate on that machine you can do the following:

    Perhaps this is flood attack. some sort of flood attack can never close opened tcp session so you may see many TIME_WAIT in netstat output. I more than sure if you had restart amount of TIME_WAIT will decreased but then again return to same value. You most likely need to isolate victim domain and deal with DDOS.
