1. Convince the client to close the connection. The initiator of the close will be the one holding the TIME_WAIT socket (for ~2 minutes)
2. Send RSTs to clients that refuse to close. RST avoids creating a TIME_WAIT state. I think this is slightly more dangerous than a normal FIN close, because wandering duplicates could interfere with the next connection. From Python, you can close a TCP socket in a way that causes a RST to be sent:
# Set SO_LINGER to 1,0 which, by convention, causes a
# connection reset to be sent when close is called,
# instead of the standard FIN shutdown sequence.
self.socket.setsockopt(socket.SOL_SOCKET, socket.SO_LINGER,
struct.pack("ii", 1, 0))
(From the patches and branch in http://twistedmatrix.com/trac/ticket/78)TIME_WAIT times can be tweaked with the net.ipv4.tcp_tw_recycle and net.ipv4.tcp_tw_reuse sysctls, on Linux systems anyway.
However if doing something like behind a single software load balancer then the number of ports available will be limited to the 65k connections since the source address/port and target address(the lb) are fixed.
The why is a pretty boring story: the number exists as a check against runaway processes or big jobs (e.g. busy servers) causing an I/O overload, so the numbers are set to a "reasonable value" by default. Of course the reasonable value is usually much lower than the system can handle, and at tuned for older common hardware.