@bob IMO there should be a sysctl flag for it, but I can't find one. You can drop them at firewall time, but there's no way to stop them from being generated in the first place.