What can we improve? Flexibility and ease of use syntax cleanup Make sensible defaults implicit 'flags S/SA' and 'keep state' now default first-match nat vs. last-match filtering inconsistent syntax for minor options terminology cleanup prune or remove route-to/reply-to etc largely obsoleted by routing code changes like multipath and multiple routing tables removing these will also improve code readability This is difficult to do without breaking existing rulesets.