So in summary this leverages ICMP redirects as the side channel attack. That seems fairly straight forward to mitigate, by disabling ICMP redirects. I believe this is already a common practice by anyone following the current CIS and/or NIST guidelines and benchmarks.