Press ESC to close

H12-811-v1-745-(多选题)如图所示的网络,通过以下哪些配置可以实现主机A不能访间主机B的HTTP服务,主机B不能访问主机A的下FTP服务?(多选)

(多选题)如图所示的网络,通过以下哪些配置可以实现主机A不能访间主机B的HTTP服务,主机B不能访问主机A的下FTP服务?(多选)

1657006167650.png

A


Acl number 3000

Rule 5 deny tcp source 100.0.12.0 0.0.0.255 source-port eq www destination 100.0.13.0 0.0.0.255

Acl number 3001

Rule 5 deny tcp source 100.0.13.0 0.0.0.255 source-port eq ftp destination 100.0.12.0 0.0.0.255

Interface GigabitEthernet0/0/1

Traffic-filter outbound acl 3000

Interface GigabitEthernet0/0/2

Traffic-filter outbound acl 3001

B


Acl number 3000

Rule 5 deny tcp source 100.0.13.0 0.0.0.255 destination 100.0.12.00.0.255 destination-port eq www

Acl number 3001

Rule 5 deny tcp source 100.0.12.0 0.0.0.255 destination 100.0.13.00.0.255 destination-port eq ftp

Interface GigabitEthernet0/0/1

Traffic-filter inbound acl 3000

Interface GigabitEthernet0/0/2

Traffic-filter inbound acl 3001

C


Acl number 3000

Rule 5 deny tcp source 100.0.13.0 0.0.0.255 destination 100.0.12.00.0.255 destination-port eq www

Acl number 3001

Rule 5 deny tcp source 100.0.12.0 0.0.0.255 destination 100.0.13.00.0.255 destination-port eq ftp

Interface GigabitEthernet0/0/1

Traffic-filter outbound acl 3000

Interface GigabitEthernet0/0/2

Traffic-filter outbound acl 3001

D


Acl number 3000

Rule 5 deny tcp source 100.0.12.0 0.0.0.255 source-port eq www destination 100.0.13.0 0.0.0.255

Acl number 3001

Rule 5 deny tcp source 100.0.13.0 0.0.0.255 source-port eq ftp destination 100.0.12.0 0.0.0.255

Interface GigabitEthernet0/0/1

Traffic-filter intbound acl 3000

Interface GigabitEthernet0/0/2

Traffic-filter inbound acl 3001

参考答案:BD