Marius,
Fair enough, my friend. In the past I used ampr-ripd on a downstream Linux server. Since my GW/AMPR-Router is now on my border, it seems to be another anomaly that's the "nature of the beast".
As with all other system applications on a router, I'll have to brush up on my C (C++) to add an argument to specify SRC IP, if needed. I'll disable the discovery, it's not that major to me, until it enters DNS LOC.
Otherwise, I'll consider mangling all packets destined to 44/8 (that may cause another security issue) to use tunl0, even for those users at my QTH not possessing a Ham license.
Thanks and 73,
- Lynwood KB3VWG