> > >Didn't got it! Why do you think you can't have all in one machine? > No I want them separate. The spaher is in one machine and the firewall is on the second machine. When I spoke about filtering I ment the classification rules and not the netfilter. >You can have your FW *and* traffic control in one machine or split it in >two if you want. >Its up to you to decide. Obviously you cannot pass marks between two >machines if you choose the splitted solution. Marks and bwcontrol must >reside in the same machine. > > > I want to classify the packets without the need of firewall. Thats what I ment. Anyway thanks for the advice Stamatis