When a packet enters the Branch Gateway through an interface, the Branch Gateway applies the policy lists in the following order:
Apply the ingress access control list.
If the ingress access control list does not drop the packet:
The packet enters the Branch Gateway through the interface.