Which forwarding rules are processed first when the user-role has mix of L3/L3 and WebCC rules?
Webcc can be enabled globally and in the user-role.
In the user-role there can be L3/L4 rules as well as WebCC rules. In such case always L3/L4 forwarding rules are processed FIRST in the flow.
ip access-list session mixrules
any any web-cc-category "gambling" deny
any any web-cc-category "games" permit
any any svc-dhcp permit
user any svc-dns permit
user any svc-icmp permit
In this example dhcp,dns,icmp rules are processed first.