I've been analyzing some of the encap traffic and finding unexpected things.
Several sources of ipencap'd packets being received by amprgw have non-44 inner source addresses.
Would you all agree that a protocol-4 (ipencap) packet reaching the UCSD gateway should always have an inner (encap'd) source address on the 44-net? And that those that don't should be considered bogus and be discarded? - Brian