What I am looking for is :
a. One ethernet card bound with modem directly and ICS installed and working. (already done)
b. Second ethernet for LAN with local IP and ICS card (item a) as gateway and DNS
c. Bound nxfilter on second ethernet (lan side) and passing internet traffic to ICS card.
basic aim is to prevent users from directly connecting to the modem for DNS. (though it can be done by blocking port 53 on modem/router, but like to do it this way)
Please suggest the possibility.