Josh, No I never have. frp is a typo - should be FTP.
access-list 101 deny tcp host 135.152.1.1 eq ftp any access-list 101 deny tcp host 135.152.1.1 eq http any access-list 101 deny tcp 131.24.194.0 0.1.1.255 eq ftp any access-list 101 deny tcp 131.24.194.0 0.1.1.255 eq http any access-list 101 deny tcp 131.24.193.0 0.1.0.255 eq ftp any access-list 101 deny tcp 131.24.193.0 0.1.0.255 eq http any access-list 102 permit tcp any any Also, "access-list 102 permit tcp any any" should be "access-list 101 permit tcp any any" Sorry, for the confusion. Cisco's focus seems to be centered on the ACL size. I am focused on a practical solution. I want clearification so I know what to practise for. Cisco's answer is: access-list 102 deny tcp 129.24.192.0 102.129.7.1 eq http any access-list 102 deny tcp 129.24.192.0 102.129.7.1 eq ftp any access-list 102 permit tcp any any Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=59260&t=58644 -------------------------------------------------- FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]

