Hi List Thanks to everyone who has offered ideas. I disconnected the Redhat server from the Lan for the whole weekend and logged all the activity happening using the iptables entry that was suggested to me by Peter Rundle. I found a definite pattern and the link is coming up every 83 minutes and some traffic is happening, about 900K received and 270K sent every time.
At the same time, logged in messages, there is an attempt to send a packet from 127.0.0.1 to 127.0.0.1 from Source Port (various between 33125 and higher) to Destination Port 53. Looking at /etc/services port 53 is the nameserver. I have never turned any DNS stuff on for this machine and I don't understand why it might be trying every 83 minutes but that would make some sense if it is trying to update it's DNS maps. The next question is how to stop these lookups every 83 minutes or how to filter them so pppd does not bring up the link. I would appreciate any help. Thanks a lot Richard -- SLUG - Sydney Linux User's Group - http://slug.org.au/ More Info: http://lists.slug.org.au/listinfo/slug