can it be solved? with first rule in my firewall config i have flush add 2 deny ip from any to any not antispoof works fine - as long as no IPv6 link-local communication is needed - route6d is an example. changing it to add 2 deny ip4 from any to any not antispoof is using link-local addresses spoofing?!