In some email I received from Peter Harrison, they wrote:
> Reply to: RE>Filtering TCP established c
> > Someone mentioned that this is done by filtering on the SYN-ACK
> > reply packet (and only this packet).
> I think the meaning of the comment was that (all) packets be filtered on the
> ACK bit, which, I believe, is what cisco is doing when they use the
> 'established' keyword. Please correct me if I'm wrong.....
But this would disallow connections in both directions, which is seldom
what is desired here (?).