在一台Cisco路由器的g0/3端口上禁上源地址为内部地址的数据包进出路由器,正确的access-list配置是
A.
Router#configure terminalRouter(confg)#interfacc g0/3Router(config-if)#ip access-group jzhfdz inRouter(config-if)#ip access group jzhfdz outRouter(config)#ip access-list standard jzffdzRouter(config-std-nacl)#permit anyRouter(config-std-nacl)#deay 10.0.0.0.0 255.255.255 logRouter(config-std-nacl)#deny 192.168.0 0.0.0.255.255Router(config-std-nacl)#deny 127.0.0.0.0. 255.255.255Router(config-std -nacl)#deny 172.16.0.0.0.15.255.255Router(config-std-nacl)#exit
B.
Router#configure terminalRouter(config)#ip access-list standard jhffdzRouter(config-std-nacl)#deny 10.0.0.0. 255.0.0.0 logRouter(config-std-nacl)#deny 192. 168.0.0.255.255.0.0Router(config-std-nacl)#deny 127.0.0.0. 255.0.0.0Router(config-std-nacl)#deny 172.16.0.0. 255.240.0.0Router(config-std-nacl)#permit anyRouter(confg- std-nacl)#exitRouter(config)#interface g0/3Router(config-if)#ip access-group jzhffdz inRouter(config-if)#ip access-group jzhffdz out
C.
Router#configure terminalRouter(config)#ip access-list standard jhffdzRouter(config-std-nacl)#deny 10.0.0.0. 255.255.255.255 logRouter(config-std-nacl)#deny 192. 168.0.0.0.0.255.255Router(config-std-nacl)#deny 127.0.0.0.0. 255.255.255Router(config-std-nacl)#deny 172.16.0.0. 0.15.255.255Router(config-std-nacl)#permit anyRouter(confg- std-nacl)#exitRouter(config)#interface g0/3Router(config-if)#ip access-group test inRouter(config-if)#ip access-group test out
D.
Router#configure terminalRouter(config)#ip access-list standard jhffdzRouter(config-std-nacl)#deny 10.0.0.0. 255.255.255.255 logRouter(config-std-nacl)#deny 192. 168.0.0.0.0.255.255Router(config-std-nacl)#deny 127.0.0.0.0. 255.255.255Router(config-std-nacl)#deny 172.16.0.0. 0.15.255.255Router(config-std-nacl)#permit anyRouter(confg- std-nacl)#exitRouter(config)#interface g0/3Router(config-if)#ip access-group jzhffdz inRouter(config-if)#ip access-group jzhffdz out