Tue Mar 15, 2011 4:56 pm
Yes, you can mark packets based off of in and out interfaces, if you wanted to group certain VLANs together I would use a Jump action in mangle to get them into a custom chain to cut down on rules depending on the number of VLANs you are looking to do this for. Also in queue trees you can set up different priorities based off of those marks, or a different QoS scheme altogether with using the parent interface as the VLAN. But it would be easier to set an overarching limit on the physical interface and then set up different limits based off of packet marks from there. How complex and fancy you want to get is up to you. Just remember the queues can only control traffic sent from the router, not what it gets, so LAN interface(s) will only affect download, and WAN interface(s) will only affect upload.
You can play with the Global-x interfaces as well, I just personally don't like to use them.