单项选择题
在一台Cisco路由器的g3/1端口封禁端口号为139的TCP和端口号为1434的UDP连接,并封禁ICMP协议只允许212.15.41.0/26子网的ICMP数据包通过路由器,正确的access-list配置是______。
A.Router(config)#ip access-list extended filterRouter(config-ext-nacl)#permit icmp 212.15.41.0 255.255.255.192 anyRouter(config-ext-nacl)#deny icmp any anyRouter(config-ext-nacl)#deny udp any any eq 1434Router(config-ext-nacl)#deny tcp any any eq 139Router(config-ext-nacl)#permit ip any anyRouter(config-ext-nacl)#exitRouter(config)#interface g3/1Router(config-if)#ip access-group filter inRouter(config-if)#ip access-group filter out
B.Router(config)#ip access-list extended filterRouter(config-ext-nacl)#permit icmp 212.15.41.0 0.0.0.192 anyRouter(config-ext-nacl)#deny icmp any anyRouter(config-ext-nacl)#deny udp any any eq 1434Router(config-ext-nacl)#deny tcp any any eq 139Router(config-ext-nacl)#permit ip any anyRouter(config-ext-nacl)#exitRouter(config)#interface g3/1Router(config-if)#ip access-group filter inRouter(config-if)#ip access-group filter out
C.Router(config)#ip access-list standard filterRouter(config-std-nacl)#permit icmp 212.15.41.0 0.0.0.63 anyRouter(config-std-nacl)#deny icmp any anyRouter(config-std-nacl)#deny udp any any eq 1434Router(config-std-nacl)#deny tcp any any eq 139Router(config-std-nacl)#permit ip any anyRouter(config-std-nacl)#exitRouter(config)#interface g3/1Router(config-if)#ip access-group filter inRouter(config-if)#ip access-group filter out
D.Router(config)#ip access-list extended filterRouter(config-ext-nacl)#permit icmp 212.15.41.0 0.0.0.63 anyRouter(config-ext-nacl)#deny icmp any anyRouter(config-ext-nacl)#deny udp any any eq 1434Router(config-ext-nacl)#deny tcp any any eq 139Router(config-ext-nacl)#permit ip any anyRouter(config-ext-nacl)#exitRouter(config)#interface g3/1Router(config-if)#ip access-group filter inRouter(config-if)#ip access-group filter out