Kmod-nft-offload | !free!
Parent controls or deep packet inspection features that look inside every packet will be bypassed once a flow is offloaded. How to Enable kmod-nft-offload in OpenWrt Method 1: Using the LuCI Web Interface Log into your OpenWrt dashboard. Navigate to Network > Firewall . Scroll down to the Routing/NAT Flow Offloading section. Check the box for Software flow offloading .
It allows the kernel to bypass the expensive task of re-evaluating every packet in a high-speed data stream against the full set of firewall rules once a connection is established. kmod-nft-offload
Your firewall rules must be written to support the flowtable directive. A typical configuration looks like this: Parent controls or deep packet inspection features that
Knowing your hardware can help determine if it supports full hardware offloading. kmod-nft-offload - [OpenWrt Wiki] package 10-Dec-2023 — Scroll down to the Routing/NAT Flow Offloading section