> I think this drops all ICMP traffic, which I don't think is a
> terrific idea. To block ping, all you want to drop is outbound
> ICMP echo-reply. The following rule would do that ...

   Why ? I've always done so in my home machine, I just
want to get answers to my echo-requests, what's wrong
with that (for a home machine I mean) ?