<seq> {permit|deny} <protocol> <src> <dst> [echo-reply|established]
Insert a line at a sequence number inside a named ACL ('no <seq>' removes it). 'show access-lists' prints the numbers.
Example
R1(config-ext-nacl)# 15 permit icmp any any echo-replyACLs are stateless: a reply is a new packet, filtered again on every router it crosses. A deny-by-default list inbound on the outside also drops the replies to your own pings — add 'permit icmp any any echo-reply' (ICMP) or 'permit tcp any any established' (TCP return traffic).
Don't just read it — type <seq> {permit|deny} <protocol> <src> <dst> [echo-reply|established] in a real network simulator in your browser and watch it take effect. No install, no account needed to start.
Frequently asked
What does the "<seq> {permit|deny} <protocol> <src> <dst> [echo-reply|established]" command do?
Insert a line at a sequence number inside a named ACL ('no <seq>' removes it). 'show access-lists' prints the numbers.
What's the common gotcha with "<seq> {permit|deny} <protocol> <src> <dst> [echo-reply|established]"?
ACLs are stateless: a reply is a new packet, filtered again on every router it crosses. A deny-by-default list inbound on the outside also drops the replies to your own pings — add 'permit icmp any any echo-reply' (ICMP) or 'permit tcp any any established' (TCP return traffic).
Example of "<seq> {permit|deny} <protocol> <src> <dst> [echo-reply|established]"
R1(config-ext-nacl)# 15 permit icmp any any echo-reply