This was the reason we had to come off the MX platform and move to the FTD platform for our firewalls. The processing if I recall correctly was L7 then L3 unless there is a 1:1 NAT then it's just the NAT rules for inbound traffic.
If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.