> This assumes the ISP manages the customer's CPE or home router, which is often not the case. Adding such ACLs to the upstream device, operated by the ISP, is not always easy or feasible.

Unicast RFP should be a feature every ISP requires of all edge
devices for at least 15 years now.  It should be on by default for
virtually all connections, and disabled only by request or when
there are circumstances to suggest it would break things (e.g. a
request for BGP with full tables over the link).

At this point there's no excuse, anyone who has gear who can't do
that has been asleep at the switch.  It's been a standard feature
in too much gear for too long.

