PF?

Default packet filter (firewall/NAT) from OpenBSD 3.0 (December 2001)

Replaced IPFilter, which had to be removed due to licensing issues (which in turn lead to a license audit of the entire OpenBSD source tree)

Based on new code by Daniel Hartmeier (June 2001 ->)

High performance (see http://www.benzedrine.cx/pf-paper.html), low maintenance