For a gateway device, why would you even need IFB? IE, eth0 = Internet, eth1 = LAN. You shape internet destination traffic on eth0 and you shape LAN destination traffic on eth1. From the perspective of 'tc' you're shaping 2 x outbound queues. In the unlikely event you're expecting traffic for the actual firewall / shaping device, just police that. But imho you don't want your gateway device to do anything apart from routing, tc, firewall, bgp. > Or is there a better way to get set up ifb after inbound NAT? -- To unsubscribe from this list: send the line "unsubscribe lartc" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html