hello John
did you try denying ICMP on the filter assigned on the public interface ?? On the filter rulesets, create a rule which will deny ICMP traffic... this should work out or deny ICMP on the outside router which is connected to the VPN 3000.
hope this helps.. all the best...
Raj