Kmod-nft-offload
You cannot offload ct state established easily because the hardware would need to maintain stateful timers. For true offload, use stateless rules or ensure tc can offload the connection tracking (requires advanced hardware with full conntrack offload, like Mellanox ASAP²).
From that day on, whenever a citizen of OpenWrt wanted to reach maximum speed on their router, they made sure to invite the hero to their system. wget / SSL issues when updating packages #17385 - GitHub kmod-nft-offload
In the realm of Linux networking, achieving optimal performance and security is a perpetual quest. One crucial component that plays a significant role in this pursuit is kmod-nft-offload . This kernel module is designed to offload nftables rules to hardware, thereby enhancing network throughput and reducing latency. In this article, we'll explore the intricacies of kmod-nft-offload , its benefits, and how it can be leveraged to supercharge your Linux network. You cannot offload ct state established easily because
By offloading nftables rules to hardware, kmod-nft-offload alleviates the CPU burden, allowing it to focus on more critical tasks. This results in improved network performance, characterized by increased throughput and reduced latency. wget / SSL issues when updating packages #17385
Are you currently seeing on your router, or are you just planning a custom build ? kmod-nft-offload - [OpenWrt Wiki] package