We have a service policy that has a "Do not match" ACL to exempt certain traffic. This ACL is followed by a Match ACL for all other traffic. When I test matching traffic on the ASA by using "show service-policy flow..." command I can confirm that t...