在一台Cisco路由器的g3/1端口封禁ICMP协议,只允许137.189.11.0/24和211.68.69.0/26子网的ICMP数据包通过路由器,正确access-list配置是
A.
Router(config)#access-list 98 permit icmp 137.189.11.0.0.0.0.255 anyRouter(config)#access-list 98 petmit icmp 211.68.69.0.0.0.0.63 anyRouter(config)#access-list 98 deny icmp any anyRouter(config)#access-list 98 permit ip any anyRouter(confg)#interface g3/1Router(config-if#ip access- group 98 inRouter(config-if)#ip access-group 98 out
B.
Router(config)#access-list 199 permit icmp 137.189.11.0.0.0.0.255 anyRouter(config)#access-list 199 permit icmp 211.68.69.0.0.0.0.63 anyRouter(config)#access-list 199 deny icmp any anyRouter(config)#access-list 199 permit ip any anyRouter(config)#interface g3/1Router(config-if)#ip access-group 199 inRouter(config-if)#ip access-group 199 out
C.
Router(config)access-list 198 permit icmp 137.189.11.0.0.0.0.255 any Router(config)#access-list 198 pemit icmp 211.68.69.0 0.0.0.192 anyRouter(config)#access-list 198 deny icmp any anyRouter(config)#access-list 198 permit ip any anyRouter(config)#interface g3/1Router(config-if)#ip access group 198 inRouter(config-if)#ip access- group 198 out
D.
Router(config)access-list 999 permit icmp 137.189.11.0.0.0.0.255 any Router(config)#access-list 999 pemit icmp 211.68.69.0.0.0.0.63 anyRouter(config)#access-list 999 permit ip any anyRouter(config)#access-list 999 permit ip any anyRouter(config)#interface g3/1Router(config-if)#ip access-group 999 inRouter(config-if)#ip access- group 999 out