I use MT primarily for bw control. I have two units running, each with 300-400 simple queue entries. In addition to limiting bandwidth, I also use the device to lock down unused or cancelled users. My question is, is it better from a CPU standpoint to lock down unused IP addresses by limiting the bandwidth to a really low amount (like 10bps) or with a drop statement using the firewall? Which is processed by the MT first? In fact, does anyone have information about the sequence of packet processing?