Our basic model is that we just move the packets, and each host is required
to do its own due diligence on filtering packets, since we in general don't
know what's going on with a given host (and usually we don't WANT to know).
In other words, we rely on host-based firewalling/filtering rather than
router-based.  There's no way that the router can make decisions about what
packets are OK for my machine as well as I can (just the machines in my office
have different rulesets, and none of them correspond to the machines in the
next cubicle over..)

We will on occasion deploy router-based filters on a *very* temporary basis as
an abatement measure (I think we put in some rules for about 72 hours for the
Nachi attacks), and there's a *few* subnet-specific rules in place (Clark's
lurking here someplace, he can address that in more detail).  But our basic
model is that every host on the network needs to be ready to do something
appropriate with any packet, from anyplace, at any time.

