The documentation for the CRS310-8G+2S+ indicates that using hardware offloading will bypass the cpu and therefore the firewall.
The first firewall filter rule allows established connections to bypass the rest of the filters for efficiency purposes.
action=accept chain=input comment="default configuration" connection-state=established,related
Will the HW offloading version of this rule cause any issues with the rest of the firewall rules being applied to new connections?
action=fasttrack-connection chain=forward comment="fast-track for established,related" connection-state=established,related hw-offload=yes
Tia