netstat -s -p ip . . . 3575124 datagrams with bad address in header Could it be this that drops "bad" packets before they enter the IPFW ?