Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

established on access-list


when I build an access-list which permit host only to talk tcp with host, and I want to use "established", why do i have to write this command:

acl 169 permit tcp host host established

instead of:

acl 169 permit tcp host host established

because as I understand the sequence of the command is "source" and then "destination".

thank you

New Member

Re: established on access-list

When you write this type of access-list you need to define who should initiate the conversation. With the command that you had to write you are defining that should initiate the conversation and traffic can go to this host from only if the established bit is set (meaning that a connection has been previously established). This being an extended access-list it should be placed as close to the source of the block as possible so you should apply it in on the interface that the 10 network comes in on. A common use for this is to restrict you local network from replying to internet connections (http) unless the established bit is set. (i.e. permit ip any eq 80 any established)

Hope this helps!

New Member

Re: established on access-list

it depends on ur network design. so it depends where u r giving your access list. since it is that u have to use and extended access list, it is always better u keep it near the source. so if u want to talk only tcp to, u take as the source and as the destination. so it is always better to keep the access list near the source and therefore

'acl 169 permit tcp host host established' is the correct command and u place the access list neat

'established' is required for the handshake process to take place fully.

now i guess ur doubt is cleared!

Anish Paul Behanan

Software Specialist, DEC (India)

CreatePlease login to create content