After some searching in Internet I can see a common agreement for SNAT to be faster than MASQUERADE due to the reduced overload. As far as I can see the NAT target (on Freshtomato at least) is defaulting to MASQUERADE. So two points of discussion here are: - Shouldn't the default NAT Target be set to SNAT by default? - I have an OpenVPN client running on my device and see references to MASQUERATE linked to tun11. Is it worthy looking into the Tomato/OpenVPN code to replace them with SNAT?