I moved to Hurricane Electric and I haven't seen this problem again.I'm on hurricane. BTW, just to be clear, the blocked attacks are identified as being from the ipv6 address assigned to utm, not the external address of the client side of the tunnel. That implies to me they are being generated inside my network, not outside. However, that's only my assumption based on the address.
Mark