Hi,
the established keyword is a weak stateful firewall implementation that was the first steful filtering done on IOS.
It looks at the flags in the TCP header and if it finds the ACK bit set then it assumes this is return traffic for traffic initiated from other side of the router and opens a hole in the ACL inbound which denies everything else.
There are more secure and advanced ways of doing stateful firewalling in IOS like CBAC or the latest ZBF.
Alain.
Don't forget to rate helpful posts.