|
发表于 2019-4-24 16:07:24
|
显示全部楼层
本帖最后由 夜半歌声 于 2019-4-24 16:49 编辑
* C1 H% {5 J& ]7 N+ S/ _, v& a9 S7 \) M) q- u' i* d: |
Question 6
$ [8 X! U% I& f; r: f- {Refer to the exhibit
; E9 N% u' T4 Q JR1#show access-list: A: |/ Y* r a/ d6 F& ?. O
IP access-list extended Super_User+ V) K) H* E' z4 _0 V
1 permit ip host xxxx host xxxxx6 Z: Q3 I7 [( F. T: h
2 permit ip host xxxx host xxxxx- r M( l- ~ i! \# [: K* b
3 permit ip host xxxx host xxxxx
% t$ f" d, h& f4 permit ip host xxxx host xxxxx
; m+ ~$ L% G# J6 g' |# `5 permit ip host xxxx host xxxxx: k g8 D- X+ F4 l# w
6 permit ip host xxxx host xxxxx
1 |0 K! }' M$ }% `& l7 permit ip host xxxx host xxxxx9 @: `! D$ L. f! Y& @$ l8 A
8 permit ip host xxxx host xxxxx! O( \+ d, l6 n! h6 T
9 permit ip host xxxx host xxxxx
( J8 q. A3 [5 g2 X N
6 i! u/ D4 C- K+ c0 O2 z& u. DWhich of the following commands inserts five additional lines to the ACL Entry Sequence between lines 3 and 4 without changing the existing configuration? Q6 D" K3 A" Y7 s! W) P* e
A R(conf)# ip access-list resequence Super_User 1 6& B3 _! @0 o) i- }: Z
B R(conf)# ip access-list resequence Super_User 1 55 s' ]+ v3 _ E% T' q6 G
C R(conf-nacl)# ip access-list resequence Super_User 1 6& [' ^0 ? U- b. _
D R(conf-nacl)# ip access-list resequence Super_User 1 5
/ F( d( ]7 `7 A' {
7 W0 S) C# \$ m; M0 b( v1 F: X$ ^3 ?这道题目,我的答案是 A6 g- E: F8 E! Q+ I# b
0 e3 B0 h% u) T以下为测试环境展示4 ]( E7 Q, t! p8 J3 o6 W/ B5 W
- R1#sh access-lists
. p9 p* j5 M0 T& A' m" Y* f# e - Extended IP access list super_user6 d# m4 ?) x' I* {5 Z
- 1 permit ip host 1.1.1.1 host 10.1.1.1
A4 N+ R9 F/ \ - 2 permit ip host 1.1.1.1 host 10.2.2.2: K$ Z6 r9 w$ ]$ a
- 3 permit ip host 1.1.1.1 host 10.3.3.3
/ q+ P j s$ \ - 4 permit ip host 1.1.1.1 host 10.4.4.4
Z, z, q6 M3 w2 F - 5 permit ip host 1.1.1.1 host 10.5.5.5
0 ]" i) v+ S+ ^8 i - 6 permit ip host 1.1.1.1 host 10.6.6.6
% i. a2 E6 {( o9 ]. H: u8 P$ A - 7 permit ip host 1.1.1.1 host 10.7.7.7/ X+ a5 H8 \" z6 Q$ k& J
- 8 permit ip host 1.1.1.1 host 10.8.8.86 a" O' G8 c7 D: ^1 b/ }- c% c
- 9 permit ip host 1.1.1.1 host 10.9.9.9
复制代码 , b: ~3 E9 k- R, R
% {$ o0 W) K% j首先验证答案 A
0 e! a$ ?7 F* {! U+ F( d/ Z8 X, D1 r
5 `( k8 O9 h5 w! x& s. A& K" X- R1(config)#ip access-list resequence super_user 1 6& N4 O8 Y' g. s. J. [" o0 G
2 R# X- C5 p) d( n) }& d% s- 验证结果如下:/ w9 k5 }3 m) T2 S
& ?! E2 S, l! R+ Z3 l& J& E- R1(config)#do sh access-lists
8 m' V2 g( z* W* J! o: ~- g6 \ - Extended IP access list super_user7 h9 K8 r+ l' F
- 1 permit ip host 1.1.1.1 host 10.1.1.14 q, N/ y& |( _0 s( j: k/ n' H O
- 7 permit ip host 1.1.1.1 host 10.2.2.2
5 X( l& p. E+ V- ^, l - 13 permit ip host 1.1.1.1 host 10.3.3.3# e/ {" o" m2 E( m9 g, O8 i, X
- 19 permit ip host 1.1.1.1 host 10.4.4.4
$ _% K8 ^ r2 }: j - 25 permit ip host 1.1.1.1 host 10.5.5.5
: W7 H' U: _- t# n/ B: m: p - 31 permit ip host 1.1.1.1 host 10.6.6.6: M; `& d& T+ T$ U9 L
- 37 permit ip host 1.1.1.1 host 10.7.7.7
# C; T4 } ~ D3 m7 J, ^, H) p. E - 43 permit ip host 1.1.1.1 host 10.8.8.8
& _+ t5 E. j$ C; ]- F - 49 permit ip host 1.1.1.1 host 10.9.9.9
; Q! n2 `# B* F' w. d: G: K ?
. F k2 H# s2 y! w! j- ] \& _- 第3行与第4行之间可以插入 14/15/16/17/18 5条acl 语句
复制代码 ( z" z! N. O. P5 j
再来验证答案B3 n k |. S" l
- R1(config)#ip access-list resequence super_user 1 5
4 j4 |3 P8 ]" e; o3 s
. U, ]# @& D: ^- 验证结果如下:3 o* R, l C- q2 B$ r) u% Y: \
- X& j: c1 I1 p4 U: H6 B8 L- R1(config)#do sh access-lists 5 a' {1 T2 W. e. w
- Extended IP access list super_user- G' O$ A# m. x6 z8 F0 j! l' x# A$ T
- 1 permit ip host 1.1.1.1 host 10.1.1.1
2 ?% Y9 G4 p5 [ - 6 permit ip host 1.1.1.1 host 10.2.2.2
5 M: l3 |8 C# t - 11 permit ip host 1.1.1.1 host 10.3.3.3
3 W$ Q! t4 Q% S8 n: c+ F8 k - 16 permit ip host 1.1.1.1 host 10.4.4.4
1 d5 W+ q7 l' z; j5 L - 21 permit ip host 1.1.1.1 host 10.5.5.5/ v: ^* O2 ]8 D4 r# y, `
- 26 permit ip host 1.1.1.1 host 10.6.6.6) \; q- T3 ?" Y* N x% j
- 31 permit ip host 1.1.1.1 host 10.7.7.76 J2 P, d0 M3 `8 P q/ {
- 36 permit ip host 1.1.1.1 host 10.8.8.80 C; C8 u2 E+ b' z$ j
- 41 permit ip host 1.1.1.1 host 10.9.9.9
- S! N% l9 p1 x0 j - 3 U6 }, z @3 h0 G3 j
- / R$ o& H+ }; m6 S/ F# h7 m
- 第3行与第4行之间可以插入 12/13/14/15 4条acl 语句
复制代码 # g- j; w" Y$ r7 L
8 j/ z+ y% e/ ]* t" p8 j$ A验证答案C6 D9 r; {" h0 u% F1 ]/ q
- R1(config-ext-nacl)#ip access-list resequence super_user 1 6* O, V: M; {6 Y0 \" l Y
- : F, E+ f+ F, y6 U
- 验证结果如下:6 I- D, u+ y& Z
- 6 |" Q3 ]4 a4 t; u
- R1(config)#do sh access-lists
1 l* Q5 Q I4 g3 Y% F" i - Extended IP access list super_user# V* a, @7 q3 n7 s: z M
- 1 permit ip host 1.1.1.1 host 10.1.1.1
6 i# e. t1 l3 k- K% x, v - 7 permit ip host 1.1.1.1 host 10.2.2.2. w' M7 q& |' o& M- t$ q6 w
- 13 permit ip host 1.1.1.1 host 10.3.3.3
5 q! t; T' ~4 o& C; D0 q - 19 permit ip host 1.1.1.1 host 10.4.4.4* t9 T" e7 ^7 ~6 r" L$ M4 `
- 25 permit ip host 1.1.1.1 host 10.5.5.5
1 l8 z% l5 `" Y# J% m$ \7 u - 31 permit ip host 1.1.1.1 host 10.6.6.6
) e. V7 d# m0 z2 Z7 B* m0 N$ ?. Z! E - 37 permit ip host 1.1.1.1 host 10.7.7.7! Q# o0 o5 z# h7 ?( e# `2 Z) S
- 43 permit ip host 1.1.1.1 host 10.8.8.8
0 l1 f+ B( Q) F! t9 J+ c - 49 permit ip host 1.1.1.1 host 10.9.9.9: {/ g2 t+ \5 L9 r! o9 i) P
- ; K# v; f6 W* C
- 第3行与第4行之间可以插入 14/15/16/17/18 5条acl 语句,验证结果与A相同
3 j5 ]9 B+ o# `% y6 U! K- c. ?
复制代码 6 v( P/ C5 M: |) q) U
6 o) O" `" j5 p/ G2 k2 b, R( |验证答案D3 j. q3 k& c" X% @; C
O9 M/ d3 }$ D. B" E2 j
4 ]- \8 K0 R6 p K2 P8 G
- R1(config-ext-nacl)#ip access-list resequence super_user 1 5
' f1 W9 I# d3 o
- a% h/ U. D0 u* B# D- 验证结果如下: b1 V/ T/ z" g9 h- x
- 3 F; t1 _, f) q3 n
- R1(config)#do sh access-lists
- m$ {) u- j; o; D3 H: I* T( i- L - Extended IP access list super_user
" _3 ?( ?% G7 W) ]0 n - 1 permit ip host 1.1.1.1 host 10.1.1.10 x; D$ X( n4 ?4 U( E( {
- 6 permit ip host 1.1.1.1 host 10.2.2.2
( l' p! i3 u0 d6 V ]0 f$ K - 11 permit ip host 1.1.1.1 host 10.3.3.39 \9 s% Q% S3 j# b2 W. _& F9 ]
- 16 permit ip host 1.1.1.1 host 10.4.4.4- r' r5 V' p# ?7 F, i
- 21 permit ip host 1.1.1.1 host 10.5.5.5
1 V8 P5 v/ W7 Q4 q" ]4 \ - 26 permit ip host 1.1.1.1 host 10.6.6.6
9 e! h. ]* b- m- F - 31 permit ip host 1.1.1.1 host 10.7.7.7
( _/ K8 j2 b& c4 F3 x - 36 permit ip host 1.1.1.1 host 10.8.8.8
$ i) q" w. b$ Y0 S1 D. u1 s6 ?& p - 41 permit ip host 1.1.1.1 host 10.9.9.9: y v. |6 P2 g" ~
; m+ e# M1 W4 h: x" X- 第3行与第4行之间可以插入 12/13/14/15 4条acl 语句,验证结果与B相同
复制代码
9 h+ V9 C! b- n+ }# K0 M$ d. k% b" ^* E q2 C
+ a/ J- T) M; M( w从验证结果上来看,AC相同,BD相同(AC/BD命令其实是一样的,区别仅在于所处模式不同)。
! X5 i$ K, R2 |1 c& ?3 c
- y3 h4 W' h: f% b1 W; d$ ^5 c7 x% P( B% W" K& Z) s
那么答案A和C有什么不同呢?我们继续验证
N9 v: ~6 C; a* J验证答案A,使用?进行提示,如果如下:1 V( v5 s+ M. S6 y. u: e _
$ g& C9 w2 ]( ~. b0 H
- R1(config)#ip access-list ?/ w+ N1 E: p8 |* `6 {4 x
- extended Extended Access List
8 k$ T* F; k& R0 h7 R - log-update Control access list log updates4 O8 X5 v% r$ p% K: R. y+ G) }. C
- logging Control access list logging
" z7 [9 F* H+ R, n - resequence Resequence Access List
- r2 r9 K o _ - standard Standard Access List
; i l3 H8 S- e( R: ]7 G9 p0 w
# P" T2 z; T4 K6 r- R1(config)#ip access-list res? " a8 v6 n" X4 d4 S7 f! q7 k
- resequence
1 y$ E n$ H3 J( R - / `: T+ g7 V5 f2 B4 R* ~7 k
- R1(config)#ip access-list res
. ^. ^5 R2 a5 h! i& L - R1(config)#ip access-list resequence ?, h0 k" V, R! Y9 s! E
- <1-99> Standard IP access-list number
( D; t0 u. Z7 e+ s5 ]6 X x' e' y - <100-199> Extended IP access-list number* K" r0 e+ e; n+ B" X' P( M- B
- <1300-1999> Standard IP access-list number (expanded range)
( f6 ]- F# r4 e: U - <2000-2699> Extended IP access list number (expanded range): |& e( c% K# ]
- WORD Access-list name
$ _0 L: }/ }* H+ Q# c, ~0 Q - % m3 O( m# v; v$ ], k' y! D
- R1(config)#ip access-list resequence super_user ?3 ^2 K# B6 F; t0 r; i- j
- <1-2147483647> Starting Sequence Number
' ?0 y) t, h8 V( V& w' o( A
# P$ X' k$ `8 F6 l0 e- R1(config)#ip access-list resequence super_user 1 ?
2 o2 e: a3 o7 S" Y* w5 Q - <1-2147483647> Step to increment the sequence number
+ G i4 p) m0 h! d7 V ?$ X: i- N: h - , g* k+ C% C3 O: T, p3 n
- R1(config)#ip access-list resequence super_user 1 6
复制代码 , j6 Y( O. g* i- X; y- W
4 T, {3 T( ]$ S* T0 J2 Y! ]' o& v( Y; C5 a% G/ I5 A% v3 R
验证答案C,使用?进行提示,如果如下:' b3 M H% e0 C3 _
" C$ T" ~! J0 c' z* L8 _5 E5 a/ k. f
- R1(config)#ip access-list extended super_user
; }8 {' |; F. w6 A! w/ z - R1(config-ext-nacl)#ip ?2 B. e, T1 l8 R! }" q2 E" O
- % Unrecognized command
, ]) {! z( ~/ h& d - R1(config-ext-nacl)#ip
复制代码 提示命令不正确了, ,虽然我直接将完整命令打上去,并没有提示有错误,命令也能执行,但是从上面的提示来看,考试要考的答案 应该不会是这个,至于为什么能执行这个命令,也许是我使用的模拟器的IOS版本较新吧。
8 I5 `: F: s( o, f% K. o k L+ P9 p, F* B
* K t6 p/ q$ O; Q7 z
经过上面的分析,我认为本题的答案是 A7 w8 m! e% g" x9 _ I
& G; ~" v6 H/ y3 Z
% ^! U; @0 w# z- b$ K5 w& r
如果分析有误,欢迎各路大神批评指正。% I; ~# Y2 o5 T
& P+ W9 h7 i7 `* ~0 k. H" g s |
72#
2019-4-24 16:07:24
回复(0)
收起回复
|