Stateful 5-tuple filtering
Source and destination IPv4 + CIDR, TCP / UDP / ICMP, ports and port ranges, in one ordered rule table across three sections — to-firewall, through-firewall and from-firewall — each with its own default verdict. List-valued source, destination and port matchers compile to native set lookups, so a rule against hundreds of CIDRs or ports matches in one pass, not a sequential scan.