As long as you stick to features that are hardware offloaded then you should be OK. See here for some recent throughput tests:
https://community.ubnt.com/t5/EdgeMAX/EdgeRouter-Lite-NAT-Firewall-performance-tests/m-p/1638994
For simple NAT/SPI firewall the throughput is great, but once you start enabling features that are not supported by hardware offloading (e.g, QoS) the performance will plummet.
Hope that helps