Does loose rpf indeed drop packets sourced from null routes? I know strict does for certain, and is the least intensive method of blocking packets sourced from a particular IP/subnet. Yes, it does. And it works pretty well.