Although the discussion of ipf/iptables capabilities is really cool, really, to toss some fodder to the original question, there are some things that will kill your firewalls performance. We tested running a vpn tunnel, can't remember exactly what, but I think it was ipf and solaris 8's vpn...