Stephen Hemminger wrote: > On Mon, 16 Jun 2008 06:27:35 +0930 > David Newall <davidn@xxxxxxxxxxxxxxx> wrote: > >> ... caused by floods of packets directed towards the internet >> link at one end or the other > Why are you letting them through. Use proper firewalling. > They didn't get through the router. These floods congested the border links (devices). > A real VPN with IPSEC would have stopped the problem. > No, it wouldn't. If you don't see this, ask and I'll explain, again. > I wouldn't put a mission critical system exposed directly to the Internet. > I didn't. Standard NAT appliances protect all ends. -- To unsubscribe from this list: send the line "unsubscribe linux-net" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html