On 2011-08-12 17:06, Christian Pernegger wrote: > Since randomly disabling TCP "offensive" TCP options like syncookies, > ECN and even SACK didn't work either, I'm now officially at my wits > end. That's a good one. Do you have any unusual routing loops or other network oddities? Just eth0 (external) and eth1 (internal)? Please post your iptables / iptables-restore script. Regards, Tyler -- "Never underestimate the bandwidth of a station wagon full of tapes hurtling down the highway. -- Andrew S. Tanenbaum -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html