In this scenario, when the first packet of a connection establishes it, the rule is triggered, and the flow is offloaded to the hardware.
Understanding kmod-nft-offload : Boosting Network Performance with Hardware Acceleration
This configuration establishes a software-based fast path.
opkg install kmod-nft-offload
As 100GbE and 400GbE NICs become common, software-only packet processing simply can’t keep up. Offloading isn’t a luxury — it’s the only way forward.
This configuration effectively excludes other traffic types (like ICMP) from the hardware offload process, which can be useful in specific network scenarios.
Bypassing the CPU for established streams drops CPU utilization from 100% down to near 0%. This frees up processing power for other critical router tasks, including: Running a WireGuard VPN server Managing local network storage (NAS) Processing complex container apps (Docker) 3. Lower Latency and Jitter
: All following packets in that conversation bypassed the King entirely. They zipped through the kingdom at lightning speed, handled by the strategist’s specialized shortcuts. The Result