Cisco CCNA (200-301)Security FundamentalsHard
A network engineer wants to allow return traffic for TCP sessions that were initiated by inside hosts to pass back through an extended ACL applied inbound on the router's outside interface, while preventing any new TCP connections from being initiated from the outside network. Which keyword should be added to the end of the permit statement in the ACL?
- Areflect
- Binactive
- Clog
- Destablished
Show answer & explanationAnswer & explanation
Correct answer: D. established
The 'established' keyword in an extended ACL matches TCP segments that have the ACK or RST flag set, which only occurs after a connection has already been initiated. This allows return traffic from sessions started by inside hosts while blocking new inbound connection attempts (which begin with only the SYN flag set), effectively providing basic stateful-like filtering on the outside interface.
Why the other options are wrong
- A. 'reflect' is used with reflexive ACLs, a different (and now largely legacy) mechanism, not a keyword on a standard permit statement.
- B. 'inactive' is not a valid ACL keyword.
- C. 'log' generates logging messages for matched traffic but does not affect which traffic is permitted.
ACL 'established' Keyword
The 'established' keyword in an extended ACL permits TCP packets with the ACK or RST flag set, allowing return traffic from internally initiated sessions while blocking externally initiated new connections.
- Only applies to TCP, not UDP
- Matches ACK or RST flags, not SYN-only packets
- Provides basic stateful-like filtering without a full stateful firewall
Memory trick: 'established' lets the reply in, but blocks the knock at the door (SYN).