How difficult would it be to get some basic level filtering at the gateway? Would be nice, to just open the few ports I actually respond to, and block ssh login attempts on port 22, stuff like that? Would help make the system more 'rf friendly' I think.