Rob,
You stated:
"When you are worried about intrusions it is probably more effective to
block IPIP packets from sources that are not in the gateway list. I do
that as well (via ampr-ripd)."
What command/script do you use to add the endpoints to iptables?
Excerpt of traffic seen on tunl0:
2016-10-10 21:50:00 3314.416 IPIP 213.57.252.71:0 -> 169.228.66.251:0
2016-10-10 23:47:41 19457.126 IPIP 213.57.252.71:0 ->
169.228.66.251:0
2016-10-11 08:07:18 27766.044 IPIP 213.57.252.71:0 ->
169.228.66.251:0
2016-10-11 17:23:19 2017.563 IPIP 213.57.252.71:0 ->
169.228.66.251:0
- Lynwood
KB3VWG