There have been bugs fixed in past for large number of rules causing performance issues, but these where fixed in patches.
6719268 enabling ipfilter causes up to 80% or more drop in packet throughput for multi-stream workloads
6859313 large number of rules in ipfilter decreases throughput performance
The latest IPFilter patch is:
Keywords: ippool ipf
Synopsis: SunOS 5.10: ippool patch
This patch requires Kernel Patch 144500-19 (or greater)
(having the latest Kernel update and corresponding ipfilter patch is always a good idea.).
Also, ippool(1M) IPF tool can be used to help reduce the amount of rules, thus make IPF a better performer.
Thousands of rules is unusual .
The idea behind using IP pool is to group IP addresses into groups (pools). Those pools can be referred by rules then.
note: removing "log" in rules will also help with performance.