Like there is no rate limiting for LOG rules, there is also no rate limiting for REJECT targets. This makes it easy to cause a DoS because of the (usually smaller) uplink can be saturated with ICMP error messages.
http://git.ipfire.org/?p=ipfire-2.x.git;a=commitdiff;h=fa8229546b11ac356ff1df733a0b17eb045559ee