No I want them separate. The spaher is in one machine and the firewall is on the second machine.
Didn't got it! Why do you think you can't have all in one machine?
When I spoke about filtering I ment the classification rules and not the netfilter.
I want to classify the packets without the need of firewall. Thats what I ment.You can have your FW *and* traffic control in one machine or split it in two if you want. Its up to you to decide. Obviously you cannot pass marks between two machines if you choose the splitted solution. Marks and bwcontrol must reside in the same machine.
Anyway thanks for the advice
Stamatis