You cannot shape incoming traffic, only police.
What you can do to test your zeroshell configuration is to add another network interface on zeroshell and change the default gateway address of the lan clients to be 10.0.0.2. Then the other network interface should have IP address 192.168.0.2 and do the routing of your LAN. Then just alter the gateway address of the clients and you are ready for testing.
i don’t want route all to 192.168.0.2 because i want all traffic pass throught 10.0.0.1, because in this nat (192.168.1.130 – 10.0.0.1) there is a firestarter firewall with some simple attack rules that i want