I was talking to someone of BSD persuasion and they noted that the ipfw feature had a count parameter which can be used to limit icmp attacks. Ie more then n number of pings and you begin to ignore the client or address range. Is there something similar for netfilter