How are ACL's processed on a Tunnel (GRE) interface?
Are the ACl's associated with an ip access-group OUT command processed before or after a packet being sent out the Tunnel interface is wrapped in the GRE tunnel packet?
Are the ACl's associated with an ip access-group IN command processed before or after a packet arriving at the Tunnel interface is unwrapped from the GRE tunnel packet?