Hi again, Although I have never received an answer to my questions I still continue asking:-)))) Has anyone have experience with classification of telnet/ssh packets coming from the router. I'm trying to match them against an extended access-list, but with 12.2(3)q this is impossible, although snmp traffic I matched.. Thanks in advance, Lora