Do not show the algorithm in the network device, hurriedly let the packet pass, otherwise detain. Network equipment is always the data packet to quickly leave the place, hurriedly go, the faster the better.
I said this may be a bit contradictory, quickly leave no can show the algorithm how to do?! The problem is, don't do what you do, you're not a professional firewall, why the garbage iptables! Do the work you can do, do well, show perfect, other to the experts, to the appropriate equipment. The algorithm in the network path is not limited to this machine, the algorithm that runs between each node in the whole path should cooperate tightly, for the network, the whole Internet is a computer, the CPU component is a combination of all network devices, IPV4, for example, all IP addresses constitute 32-bit address space.
The role of the router, the firewall