> >>If so, I would not spend too much time into optimizing. > do you see some blocking points to not keep it at the begin of FORWARD ? It does not work with NFQUEUE (requires PFEFW-Accept, which is also slow)?