This happens because of router redundancy. Case in point: suppose
vampire is selected via IPv6 router discovery, but radius owns the
external tunnel. Then vampire will forward the packet over the
backbone to radius, which mustn't reject it.
(This isn't a security problem because the untrusted network isn't (by
definition) trusted very much for anything.