That's a complex question:Hardware / NIC drivers matter (native Netmap drivers perform better for sure), the pattern matching algorithm (Hyperscan may be faster), the number of rules you use.Generally:Very often IPS traffic <<< non-IPS traffic. 50% off isn't so bad. Cheers,Franco