I think your second rule is wrong. When packets go out of the WAN interface NAT has been applied so the source address no longer is 192.168.1.1. Better match incoming interface and source IP only. If you want to shape something you will have to do it when traffic goes from the high speed interface to the slow. There is no point shaping from the WAN to LAN.