Hi, Thanks your help.
The port number eg, 1500, is just example. Sorry for making any confuse. By the way, if I omitted the first entry in this ACL access-list 102 permit tcp any any gt 1023 established access-list 102 permit tcp any any eq telnet interface s0 ip access-group 102 in Will the inbound traffic be blocked (implicit deny any at the end) as I only allow telnet in this ACL? The first entry I want to ensure that the TCP connection initiated from the LAN1 can be connected back. Thanks. rgds, Lo Ching Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=66591&t=66584 -------------------------------------------------- FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]

