A nice article overall, but at least some firewalls offer some flexibility with respect to dynamically blocking traffic from hosts which behave in some undesirable fashion. OpenBSD's PF has 'overload' rules for this and similar purposes.
I have included an example of this with some discussion ...
Peter N. M. Hansteen
I have included an example of this with some discussion ...
[ more ]