In all the recommendations for firewall rules, there seem to be a ream of block 192.186/16 127/8 etc rules to prevent such unrouteable addresses from coming in on your interface. If my interface is 12.34.56.78 netmask 0xffffff00, how could such packets be accepted by it anyway? Patrick