VPN provides confidentiality, integrity and availability through tunneling and encryption. Protocols used in VPN provide various security features but it does not provide any protection against Denial of Service (DoS) attack. DoS attacks to VPN represent a serious threat to organizations using Internet for communication. It also barricades the services provided by the service providers. Malicious traffic enters into the Internet only through the edge network. To provide a continuous VPN service, a protection mechanism is to be added at the edge of customer's network. This paper discusses such protection mechanisms based on filtering.