ARP Flood Attacks from Netgear Routers - Ideas?

The last time we had an issue with customer equipment taking out a sector was on barely-managed 802.11 gear. Canopy has tons of options that stop this junk. How is your equipment set up?

For the last 7 years I've been running a variation of this (grabbed this from a 13.2 PMP-450)

AP
- SM Isolation: Option 1

- Packet Flooding: Bridge Flooding Disabled
- Broadcast Downlink CIR: 200 kbps

- Protocol Filtering: IPv4 Multicast up & down

SM

- Protocol Filtering: SMB, Bootp Server, IPv4 Multicast up only

Haven't enabled the SM-side broad/multicast rate limiter. The SM isolation is key.