@coleens_ personally, I prefer wide open networks that support the internet as designed. Blocking ICMP? That’s a paddling. Blocking experimental IP traffic? Into the Iron Maiden with you!
Why would I make things harder on myself? It’s called zero trust: I’m not going to trust that my firewalls work, so let’s use end to end mutual authenticated encryption for all the things!