Cisco router: reverse ACL
Ip access-list extended REFLECTACLIN
Evaluate FROMINSIDE
Deny ip any any log
The most important statement is evaluate, which automatically inserts ACL according to the reflected ACL of FROMINSIDE to allow return packets.
Ip access-list extended REFLECTACLOUT
Permit tcp any any reflect FROMINSIDE