I'm having a bit of trouble getting ACLs to work on a baseline 2920. I create my acl, and add it to a classifier, set the behaviour to filter - permit, and i still get packets accessible where they shouldnt be. The ACL in the classifier as a "(fail)" next to it, does anyone know what I'm missing?