I was trying to set up accesslists on an interface on a 2948G-L3 switch last night for an hour to no avail. The switch showed my access-list when doing a sh ip int fa47 and the list was correct. I even applied a new list stating only deny ip any any. Traffic still came through . It was applied correctly as inbound as well. I did show logging and saw: 45w4d: ACL card not present for interface FastEthernet47 45w4d: %SYS-5-CONFIG_I: Configured from console by vty0 (172.16.10.100) 45w4d: %SYS-5-CONFIG_I: Configured from console by vty0 (172.16.10.100) 45w4d: ACL card not present for interface FastEthernet47 45w4d: %SYS-5-CONFIG_I: Configured from console by vty0 (172.16.10.100) It looks like I need and ACL card. I never heard of this, has anyone else? This is an $8000 switch capable of CEF, MLS and a while bunch of other features. Please don't tell that with all these features it can't do access-lists as is. Its classified as a distrubution layer switch, where ironically Cisco says to put your access-lists in their design model and I can't seem to get it going. any help would be appreciated... sam sneed Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=16810&t=16810 -------------------------------------------------- FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]

