Hi!, I need to deploy a new bridge+firewall+traffic shape and the only question needed to solve is the traffic shape from web named virtual hosts, ie, single ip with some domains. The idea to do it is put an inverse squid for only shape (without caching) but the patch for squid + tc [1] is for src address. Another idea is mark packets with a specific http 1.1 header (the destination server name ) but I think this is impossible with iptables... :( Is there a way to do this ? Best regards --- David [1]http://www.docum.org/stef.coene/qos/faq/cache/65.html <email scanned for viruses by Declude Virus>