Hi, is there a significant overhead when using policy filtering using
tags instead of the tradicional pass in on ext_if proto tcp port blabla,
pass out on int_if proto tcp port blabla, etc?
I like the tags better, it seems a cleaner solution, my pf.conf has
fewer lines now, what do you recomend?

