The
first two rules together allow internal users to surf the Web: The first rule allows any
TCP packet with destination port 80 to leave the organization’s network; the second
rule allows any TCP packet with source port 80 and the ACK bit set to enter
the organization’s network.