-## Certainly don't allow ping to broadcast addresses.
-run iptables -A check-icmp -g forbidden \
- -p icmp --icmp-type echo-request \
- -m addrtype --dst-type BROADCAST
+## Certainly don't allow ping to broadcast or multicast addresses.
+case $forward in
+ 1)
+ run iptables -A FORWARD -g forbidden \
+ -p icmp --icmp-type echo-request \
+ -m addrtype --dst-type BROADCAST
+ run iptables -A FORWARD -g forbidden \
+ -p icmp --icmp-type echo-request \
+ -d 224.0.0.0/8
+ run ip6tables -A FORWARD -g forbidden \
+ -p icmpv6 --icmpv6-type echo-request \
+ -d ff00::/16
+ ;;
+esac