i am using Cisco PIX Version 6.3(3) firewall. i would like to block internet access by ip. the problem is when i add the rule it falls under the rule access-list acl_out permit tcp any any eq www. it does proccess them in order right? here is the rule i am using: access-list acl_out deny ip 10.109.7.0 255.255.255.0 any. problem is it is about 30 lines down passed the permit any rule. is there a way to move it up or have a higher priority? thanks for any help.