For example all the NICs included in the Intel PRO/1000 Adapter Family are supported by Linux using the e1000.ko Kernel module.
I never tested the traffic shaping with bandwidth of 400Mbit/s. I think that the problem could exist if you use a lot of Classifier Rules which include Layer 7 filters.
Please, let us know the result of your tests.
The Zeroshell be running at bridge mode of course, the shaping rules be working only for P2P traffic anything else be at default traffic policy, the rules be as less is possible but has many is necessary to catch, find, intercept traffic P2P L4/L7, right now I’m guessing if the best location be after or before the firewall.