> Just place an outbound filter on the "OUT" port denying packets
> with a destination address for your "INSIDE" networks.
I think this solution would not generate the "network unreachable" message.
I don't want the packets to disappear into a black hole. I want them to
generate an error.
> > Obviously some gear can do this or any packet that was destined for the v
>> oid
> > would play ping-pong forever.
>
>
> Only until the Time-To-Live expires.
oh,
yeah.
forgot about that.