> Blocking ICMP completely breaks PMTUD. Which leads to all
> sorts of "funny" breakage from the end users point of view.

Surely you're in full control of the MTU between your firewall and
external router? Letting the border router deal with PMTU isn't
necessarily a bad thing.

