Access-list 102 is applied to the outside interface incoming. When I type, "show access-list 102" I get varying output.
I always get the numbered ACEs from the config. For example: 10 permit tcp any host 192.168.0.20 eq smtp (1912 matches) 20 permit tcp any host 192.168.0.20 eq www (41 matches)
Most of the time there are a varying number of statements BEFORE the first numbered ACE in the output. These statements are NOT in the config. For example: permit icmp any host 192.168.0.30 time-exceeded (1179 matches) permit icmp any host 192.168.0.30 unreachable (5342 matches) permit icmp any host 192.168.0.30 timestamp-reply permit icmp any host 192.168.0.30 echo-reply (5304 matches)
Has anyone seen this behavior before? Why are these statements present in the "show access-list" command output?