Security

<seq> {permit|deny} <protocol> <src> <dst> [echo-reply|established]

Insert a line at a sequence number inside a named ACL ('no <seq>' removes it). 'show access-lists' prints the numbers.

Works on: Router, FirewallMode: acl

Example

R1(config-ext-nacl)# 15 permit icmp any any echo-reply
Watch out

ACLs are stateless: a reply is a new packet, filtered again on every router it crosses. A deny-by-default list inbound on the outside also drops the replies to your own pings — add 'permit icmp any any echo-reply' (ICMP) or 'permit tcp any any established' (TCP return traffic).

Run this command live

Don't just read it — type <seq> {permit|deny} <protocol> <src> <dst> [echo-reply|established] in a real network simulator in your browser and watch it take effect. No install, no account needed to start.

Open the lab

Frequently asked

What does the "<seq> {permit|deny} <protocol> <src> <dst> [echo-reply|established]" command do?

Insert a line at a sequence number inside a named ACL ('no <seq>' removes it). 'show access-lists' prints the numbers.

What's the common gotcha with "<seq> {permit|deny} <protocol> <src> <dst> [echo-reply|established]"?

ACLs are stateless: a reply is a new packet, filtered again on every router it crosses. A deny-by-default list inbound on the outside also drops the replies to your own pings — add 'permit icmp any any echo-reply' (ICMP) or 'permit tcp any any established' (TCP return traffic).

Example of "<seq> {permit|deny} <protocol> <src> <dst> [echo-reply|established]"

R1(config-ext-nacl)# 15 permit icmp any any echo-reply

More Security commands

← Back to the full command reference