Dynamic Access Lists solve a different problem that traditional ACLs cannot solve quickly. Imagine a few users accessing a set of servers. ACLs match user host IP addresses. The legitimate user’s IP address changes if she borrows a PC, uses DHCP, takes her laptop home, etc. Each new IP address requires editing a traditional ACL. This caused painful administration and security holes.

An extended access list, a reflexive access list allows for the dynamic combination of two access lists. If the outbound access list recognizes a remote connection, the inbound access list will be activated to permit bidirectional traffic. With the conclusion of this interactive session, the remote host is once again denied access to the inbound access list.