+## Also, don't forward link-local broadcast or multicast.
+run iptables -A FORWARD -g bad-destination-address \
+ -d 255.255.255.255
+run iptables -A FORWARD -g bad-destination-address \
+ -m addrtype --dst-type BROADCAST
+run iptables -A FORWARD -g bad-destination-address \
+ -d 224.0.0.0/24
+for x in 0 1 2 3 4 5 6 7 8 9 a b c d e f; do
+ run ip6tables -A FORWARD -g bad-destination-address \
+ -d fe${x}2::/16
+done
+