You might be able to "show ip access-list EF-CLASS-ACL" and see which line is taking hits Also, would be curious to see what this shows also... sh policy-map interface g0/24 -Aaron