ip access-list extended REFin
permit icmp any any echo-reply !!匹配ICMP的应答包
evaluate test !!自反,放行由R1主动发起的Telnet回程流量 ip access-list extended REFout
permit tcp any any eq telnet reflect test !!当R1主动发起telnet到R3,创建自反表项
permit ip any any !!放行由内而外的所有流量
!!!!!!!!!!!!!!!!!!!!!!!! interface Serial0/1
ip address 192.168.23.2 255.255.255.0
ip access-group REFin in
ip access-group REFout out