We have testet it against a ASA5516 firewall with the linux command hping3 -1 -C 3 -K 3 -i u20.
We have the following config as stated in the suggestions.
icmp unreachable rate-limit 1 burst-size 1
icmp deny any time-exceeded WAN
icmp deny any unreachable WAN
The firewall reaches 80%-90% CPU and max 20.000 new connections pr second and is practically unreachable.
This is on version 9.6(2)1
Not sure which versions the workaround works on, but is seems to not work on 9.6(2)1 (or I might be missing something)