Large proxy-fw ipac-ng setup for ethernet clients

Hi.... I have a large network (to my standard...thats 500+ machines)
proxied by an iptables+squid woody box. I have quite a few bw hogs but
we dont want to just close the hog ports or use squidguard..... we want
to just detect the abusers and reduce them to squirming piles of green

Im wondering if any of you have tested ipac-ng for this kind of
thing..... my rules would have to be many (like 500 logging rules, one
for each client ip)...

This tool is sorta made for slip access, thats why i ask...

The box is ridiculously big, so procesing power is not my concern

Alex Borges (lex) <alex@co.com.mx>
Step One Group

