Hello Kings, I think for VPNs terminating on the ASA, the "match tunnel-group" command matches the post-decryption traffic ( plain-text ).
Cheers, TacACK
_______________________________________________ For more information regarding industry leading CCIE Lab training, please visit www.ipexpert.com
