Hi guys, CBAC needs that all connections are denied in order for it to manage who passes and who doesn't. But having a proxy, and therefore the need to stop all the PCs but the proxy, will allow anyway the PCs to go to the Internet. So, how to solve the problem? I thought about the route-map with the unwished traffic forward to NULL. Has anybody tried this solution? Which is the order between route-maps and ACL applied on a interface? TIA Alex.