I think the question is what sensible defaults should be. In my 
environment we turn off proxy-arp and redirects, and it is my firm belief 
that this is actually what should be the default.

In my opinion:

A host SHOULD support listening to redirects and MUST have a knob to turn 
off this listening if implemented. A router MUST have redirects off as 
default but MUST support a knob turning them on and when sending a 
redirect it MUST forward the packet that generated the redirect.

I know most of the above is completely against current standards, but for 
me these are more in tune with todays reality in networking as I see them.

