Intel N150 can run snort3 on symmetrical 1000 MBit line without CPU saturation

Ah! I found the culprit, in /etc/config/firewall

 option flow_offloading '1

When I remove that (luci: network>firewall> Routing/NAT Offloading>Flow offloading type
should be set to none), snort sees all the packets it should and actually loads the CPU: