- 论坛徽章:
- 7
|
RT,
发现服务器有好多线程在 send 处被阻塞住了,发送不出去
1. 阻塞端的 netstat 结果如下:
tcp 14 256960 192.168.5.16:5433 192.168.5.19:14245 ESTABLISHED
tcp 14 289080 192.168.5.16:5433 192.168.5.19:14242 ESTABLISHED
tcp 14 256960 192.168.5.16:5433 192.168.5.19:14247 ESTABLISHED
tcp 14 273020 192.168.5.16:5433 192.168.5.19:14248 ESTABLISHED
tcp 14 256960 192.168.5.16:5433 192.168.5.19:14241 ESTABLISHED
tcp 14 256960 192.168.5.16:5433 192.168.5.19:14246 ESTABLISHED
tcp 14 289080 192.168.5.16:5433 192.168.5.19:14243 ESTABLISHED
tcp 14 289080 192.168.5.16:5433 192.168.5.19:14244 ESTABLISHED
tcp 14 256960 192.168.5.16:5433 192.168.5.19:14240 ESTABLISHED
tcp 14 285608 192.168.5.16:5433 192.168.5.19:14249 ESTABLISHED
2. 阻塞端的 iptables 如下:
Chain INPUT (policy ACCEPT)
num target prot opt source destination
1 ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:53
2 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:53
3 ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:67
4 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:67
Chain FORWARD (policy ACCEPT)
num target prot opt source destination
1 ACCEPT all -- 0.0.0.0/0 192.168.122.0/24 state RELATED,ESTABLISHED
2 ACCEPT all -- 192.168.122.0/24 0.0.0.0/0
3 ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
4 REJECT all -- 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable
5 REJECT all -- 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable
Chain OUTPUT (policy ACCEPT)
num target prot opt source destination
|
|