Under vanilla IOS, is it possible to use both TCP flags (established, syn, rst, etc.) and service object groups? For example, I can create an ACL that only allows return traffic from established Telnet and SSH connections:ip access-list extended DEMO...