        This sort of feature could be easily added into a NAS, but I
     question your implementation details. If this filter was turned on by
     default, then this could "break" other types of services which may
     require source ip addresses other than the one which was negotiated to
     the user.
        This would mean that a customer could perform a flash upgrade and
     find that their service no longer operates (a technical support
     nightmare). Would you be willing to consider such a feature where it
     would have to be enabled (and is disabled by default) and a very well
     explained document with the release notes to service providers
     advising them of the risk of not enabling this switch??
