Hi, When i 'sh mls netflow ip', i can see packets that should be filtered on the interface, so could this be, because netflow shows me the packets before they are filtered by the ACL ? Regards