All Firewall rules imply actuall inspecting the data that goes thru the router, and that takes CPU time.
Arguably Layer-7 takes the most time, especially with big patterns.
NAT takes time and memory. Each NATed connection eats about 340 bytes of RAM. If you use all 65535 ports, that’s about 21Mb of RAM just for the NAT tracking records.
The simple rule is to use as few ‘hungry’ rules as you can get away with, unless your router has endless RAM and oodles of CPU power.
yes, that’s the right place. you have to come yourself, as that’s the best way to learn. you will be able to watch, just like this, but that’s not the same: