Then it has to be packet rejection on the Linux machine
Spoofing protection (IOW allowed clients on the private side) on the outgoing is forcing things not right.
Or, to put it another way:
making sure who you are and who you claim to be is the same thing. From an ARP perspective and packet mangling. Usually an "interface rule"
--
[link|mailto:greg@gregfolkert.net|greg],
[link|http://www.iwethey.org/ed_curry|REMEMBER ED CURRY!] @ iwethey
Give a man a match, he'll be warm for a minute.
Set him on fire, he'll be warm for the rest of his life!