Hello,
With simple 5-tuple filter terms and "accept"/"discard" action, the firewal filter' tested scale upper limit without degradation lies in hundreds of thousands on high-end Juniper routers. Such filter takes long time to commit though.
If You are after more complicated action like "next term", then there is a degradation since with "next term" action You are forcing a second lookup on the same packet and hence Your PPS goes down.
If is entirely possible to construct a complex firewall filter severely degrading performance but having no real world applicability.
HTH
Thx
Alex