DNS resolution is occasionally delayed and occurs at early peak hours of work.
Look at the System log error as follows:
11:04:54 it-aa kernel: [3390259.778899] nf_conntrack:table full, dropping packet.
11:04:54 it-aa kernel: [3390259.836110] nf_conntrack:table full, dropping packet.
11:04:54 it-aa kernel: [3390259.838981] nf_conntrack:table full, dropping packet.
11:04:54 it-aa kernel: [3390259.838988] nf_conntrack:table full, dropping packet.
11:04:54 it-aa kernel: [3390259.856867] nf_conntrack:table full, dropping packet.
11:04:54 it-aa kernel: [3390259.857409] nf_conntrack:table full, dropping packet
Reason:
The State Firewall's session table is full of error
Workaround:
echo ' 655360 ' >/proc/sys/net/nf_conntrack_max
sysctl.conf add
Net.nf_conntrack_max = 655360
Executive Sysctl-p
Reference: http://blog.sina.com.cn/s/blog_541a3cf10101b3bj.html
DNS resolution occasional delay