I am using IMQ on my firewall to manage downloads by two networks within the firewall. I mark traffic in iptables, and jump to IMQ from postrouting. This allows me to manage the traffic coming from the internet even though it is leaving on 2 interfaces, however I think I've hit a limitation of IMQ. If the firewall machine downloads from the internet link then postrouting rules are not hit in iptables. I did try putting a rule in input jumping to IMQ, but I wasn't particularly surprised when I didn't see the traffic on imq0.
Is there a way to manage the input traffic to the firewall from the internet alongside the two internal networks? I guess policing might be the only option?
Thanks _____________________________________________________________ David Watson, Network Manager, Team17 Software Ltd. Phone: +44-1924-267776 Fax: +44-1924-267658 _____________________________________________________________