Is there a way to display the matches on an ACL used in a policy-map (normally I'd use 'show ip access-lists') I've read its something to do with how the ACL is processed in H/W or S/W.
The following command also shows '0'
'sh policy-map interface fa0/20 input' but I know the policy is working (tested and snmp monitor)
C3560-24TS 12.2(25)SEE2 IPBASE image
This is an ASIC limitation on the 3560/3750 switches. It doesn't keep any ACL or QoS policy counters for packets switched in hardware.
You can use 'show mls qos interface statistics' if you want to see some general info about whats going on with QoS.
4500 and 6500 dont have this limitation.