>Before marking squid packets you have to define route with "ip" >iproute2 command more info could be find on www.lartc.org , below is >an example of iproute + iptables for your firewall machine. As for my part, I (plan to) go with an ebtables solution, which does not involve all the bothering with routing. Of course, you need to need to know etherbridges :)