Resheto is a firewall management tool with (not yet)optimizing rule compiler. By now it is iptables/ipset oriented but will support PF in the future(and may be others) It is suitable for big(thousands) object databases with hierarchical(nested) groups an