|
发表于 2019-4-24 16:07:24
|
显示全部楼层
本帖最后由 夜半歌声 于 2019-4-24 16:49 编辑
. Q: |- E) r/ n1 D* e; M' G% \) ?1 V; ?
Question 6
4 v0 n- D. u3 e8 q3 {Refer to the exhibit7 R$ h: \6 d B* Y: @' J5 a
R1#show access-list
7 N# X0 w2 z% {& g% W& m% rIP access-list extended Super_User( C3 _0 ?3 `' [- R% P# W
1 permit ip host xxxx host xxxxx/ W# m9 m i* Y, K
2 permit ip host xxxx host xxxxx, ~& A) V: \( z5 b
3 permit ip host xxxx host xxxxx
* ~0 n( B4 R# I# n% G& t4 permit ip host xxxx host xxxxx
9 j5 I; w% c) | a5 permit ip host xxxx host xxxxx
. N: ?; n8 P* i0 {+ H# i9 w6 permit ip host xxxx host xxxxx & e+ p% b; p! x, o
7 permit ip host xxxx host xxxxx
5 w V |& v, C" l8 permit ip host xxxx host xxxxx+ f+ M0 u, r. b: M
9 permit ip host xxxx host xxxxx5 Q4 Y! X# r5 z! t0 ]' ]* i
* W/ n' Q0 D$ L1 O
Which of the following commands inserts five additional lines to the ACL Entry Sequence between lines 3 and 4 without changing the existing configuration?
9 H8 n) v, D6 Y" @, F4 J$ PA R(conf)# ip access-list resequence Super_User 1 6
4 j" Y% U' X) VB R(conf)# ip access-list resequence Super_User 1 5
# p9 r! a$ g& ?% IC R(conf-nacl)# ip access-list resequence Super_User 1 6
" P# n2 f: m7 Z! i2 ND R(conf-nacl)# ip access-list resequence Super_User 1 5- c5 @& \9 v1 Y& K- Q
/ h# X3 F# P* c" e0 }: B: \5 A这道题目,我的答案是 A' U! p5 G3 z) j% p' w0 P0 X2 L
& c+ |: N8 V/ ^以下为测试环境展示2 ^$ @7 p2 j4 o2 _3 t5 }
- R1#sh access-lists
0 N w; V! a$ ?5 ^ - Extended IP access list super_user
7 A% O# i n1 Q - 1 permit ip host 1.1.1.1 host 10.1.1.11 T( s# q" `2 T* n3 X
- 2 permit ip host 1.1.1.1 host 10.2.2.2$ Y; v% R _. v. L3 j
- 3 permit ip host 1.1.1.1 host 10.3.3.3
# h: e1 i% Q1 b j6 ? - 4 permit ip host 1.1.1.1 host 10.4.4.4
( `& S2 \5 R# q% a" j/ H* r% p" }9 Q - 5 permit ip host 1.1.1.1 host 10.5.5.5( p7 o8 B# t* o M2 o/ G
- 6 permit ip host 1.1.1.1 host 10.6.6.6
9 J! r0 \( A; E. N0 X+ Y+ u/ l1 K1 J - 7 permit ip host 1.1.1.1 host 10.7.7.7" C( F6 V6 \. D! g* W3 C8 q: A
- 8 permit ip host 1.1.1.1 host 10.8.8.8
& \# ]6 L8 C. |# T8 z" Z - 9 permit ip host 1.1.1.1 host 10.9.9.9
复制代码 2 J" x# \2 ]; g3 f
& `; Q Z8 G, X! g% L5 h. F
首先验证答案 A
% h/ {9 E( F/ o4 z% r& U- r3 Q' m1 e {( J) j* D
- R1(config)#ip access-list resequence super_user 1 68 o* o9 \. a3 Y% x6 a* [ u, M
$ F- d9 z9 J8 ~$ A% I- 验证结果如下:- x5 p2 q$ G; w# e( Q
- I( c1 L0 m8 p: e
- R1(config)#do sh access-lists
3 F, f7 X# m" ^* U9 h: ? - Extended IP access list super_user
' F9 c1 s& t" s( |% R5 U - 1 permit ip host 1.1.1.1 host 10.1.1.1
; l0 a4 u* t: g6 k - 7 permit ip host 1.1.1.1 host 10.2.2.20 W: b: s! S1 G$ v! z# X$ D
- 13 permit ip host 1.1.1.1 host 10.3.3.3
3 K' x- A# [- d5 O - 19 permit ip host 1.1.1.1 host 10.4.4.4* o9 H( \; `, O# J1 R
- 25 permit ip host 1.1.1.1 host 10.5.5.51 D) D: \# }& T7 ~# P2 ]+ s
- 31 permit ip host 1.1.1.1 host 10.6.6.6) f B+ x9 D$ b1 g9 W" l
- 37 permit ip host 1.1.1.1 host 10.7.7.72 A' A9 ]& ~" {7 J7 m
- 43 permit ip host 1.1.1.1 host 10.8.8.8
' i2 N* O% s* l0 `7 T3 L - 49 permit ip host 1.1.1.1 host 10.9.9.9
5 [- c6 _ R' o7 D/ I" u/ K: W
1 j% z) B: N; ]0 W# d+ M& c- 第3行与第4行之间可以插入 14/15/16/17/18 5条acl 语句
复制代码 & V) G2 l9 E o
再来验证答案B
! L) C1 x @! @0 a- R1(config)#ip access-list resequence super_user 1 5
+ q" y/ ?' b0 j( J4 p! a4 k& j Y - {: [. N$ E1 v* W4 d2 C
- 验证结果如下:
4 z: k' ]- E4 |7 w. }
{0 [, ~7 w6 u* ^ ~" @# I- R1(config)#do sh access-lists 8 V8 E5 N3 J! B
- Extended IP access list super_user
7 Y/ `0 B# ?) |; y# D v - 1 permit ip host 1.1.1.1 host 10.1.1.1' x; A: z1 e& Z0 t( K
- 6 permit ip host 1.1.1.1 host 10.2.2.2/ f0 D0 l c/ ?7 s5 t3 N( `
- 11 permit ip host 1.1.1.1 host 10.3.3.33 a$ h: T w D( s4 y' S/ o
- 16 permit ip host 1.1.1.1 host 10.4.4.4
. r2 k, `# U7 Y3 |# {- h - 21 permit ip host 1.1.1.1 host 10.5.5.5. n+ O" _2 m" D- i
- 26 permit ip host 1.1.1.1 host 10.6.6.6
# d, l* h4 ?9 y. H) ^ - 31 permit ip host 1.1.1.1 host 10.7.7.70 A+ ^1 a/ n* q: j" C! f" u/ E
- 36 permit ip host 1.1.1.1 host 10.8.8.8
1 c9 x t! T. {2 k% P0 H - 41 permit ip host 1.1.1.1 host 10.9.9.9# q% C- j( F0 c9 q. _) k9 a1 L
# T* x0 g2 v! t" }9 P
) w6 t- S% n9 J' A/ M0 t7 S- 第3行与第4行之间可以插入 12/13/14/15 4条acl 语句
复制代码
) m1 t2 Z; a: _8 J4 k: M8 c1 d" T$ T! A* r: Z" Y( a
验证答案C5 N) M2 u- x; k6 z: g0 K
- R1(config-ext-nacl)#ip access-list resequence super_user 1 6
# e) L0 |) f: n+ Z8 v - m: Z l5 M! e$ ^3 F' |- c
- 验证结果如下:) Y% O: p6 G9 [' P& ]
- 7 a6 q# V) i, b% O
- R1(config)#do sh access-lists z. P+ f& z) t5 ]
- Extended IP access list super_user+ N E; ] \( ^! s0 S0 b$ C
- 1 permit ip host 1.1.1.1 host 10.1.1.1
2 S* n' J+ X/ B - 7 permit ip host 1.1.1.1 host 10.2.2.2" u; T( j7 Y( v c; F/ Q" J+ }
- 13 permit ip host 1.1.1.1 host 10.3.3.3
# Z4 C" Z% y- J - 19 permit ip host 1.1.1.1 host 10.4.4.4; M: _+ c4 B, x
- 25 permit ip host 1.1.1.1 host 10.5.5.5
+ K+ x5 I5 ~/ I$ V - 31 permit ip host 1.1.1.1 host 10.6.6.6
/ t" Z7 I7 E, [0 q3 x7 b' {" I( y - 37 permit ip host 1.1.1.1 host 10.7.7.7& [1 p H% g$ g a
- 43 permit ip host 1.1.1.1 host 10.8.8.8$ m: G, o5 o8 }1 a0 p1 v; j1 y
- 49 permit ip host 1.1.1.1 host 10.9.9.9" j/ O0 f! ^ X! N
- 9 T3 e- f- E" H; x% }
- 第3行与第4行之间可以插入 14/15/16/17/18 5条acl 语句,验证结果与A相同$ P# _1 b4 ~9 k. }& A% _; H( y6 R
复制代码
+ H2 U/ B7 \" o0 h
4 y: [1 u# {" t9 T9 J验证答案D
9 l8 E( K" ~: P/ X; x6 |' ^! S" D
# j7 f& E& Z* i5 p( M; I
- Y8 y/ I8 g% j% y6 U K/ m- R1(config-ext-nacl)#ip access-list resequence super_user 1 5
7 `2 H3 L$ x$ h" s% s m
7 T5 z1 X/ G1 H# |/ d9 G- 验证结果如下:& n3 i8 L* n6 x/ Z% ^
0 n! [# d, a. Z: x- z* |- R1(config)#do sh access-lists3 u% u) x# N/ e& L
- Extended IP access list super_user
; P. _$ y" Y9 m% g& n, M. a - 1 permit ip host 1.1.1.1 host 10.1.1.1. n8 }! a1 c( P3 S0 P7 `( K; w
- 6 permit ip host 1.1.1.1 host 10.2.2.2
1 @" S0 S; I0 d5 `4 p2 V/ a - 11 permit ip host 1.1.1.1 host 10.3.3.37 ]( Z- E% z% C2 N; J$ ]6 r
- 16 permit ip host 1.1.1.1 host 10.4.4.4
, w* G) B& N4 Y) e# r6 o - 21 permit ip host 1.1.1.1 host 10.5.5.5; B @! N: e0 P/ E; t. b2 ]
- 26 permit ip host 1.1.1.1 host 10.6.6.6
; W3 x5 K0 Z; n! J - 31 permit ip host 1.1.1.1 host 10.7.7.7
) F4 A9 w0 W2 \9 ^+ Z" V v - 36 permit ip host 1.1.1.1 host 10.8.8.8/ c+ u2 [! }+ T" J0 j3 P; E
- 41 permit ip host 1.1.1.1 host 10.9.9.9
* J* V, h9 }6 j - 3 ~4 l# {* J- h2 M' {- M
- 第3行与第4行之间可以插入 12/13/14/15 4条acl 语句,验证结果与B相同
复制代码 % b* L" t E% N1 B( U
, ]/ Z" M3 p9 y8 g0 b
2 i8 N& j/ M. `从验证结果上来看,AC相同,BD相同(AC/BD命令其实是一样的,区别仅在于所处模式不同)。0 n; N8 t3 X2 n" X- v5 l
* @# k0 E- A F( G( x; r
$ ?9 z' V/ o m( J
那么答案A和C有什么不同呢?我们继续验证
+ k7 h% B/ H: W0 S8 J验证答案A,使用?进行提示,如果如下:8 c- l0 W7 f! C
2 h% Y! b: q1 }! ?- Z# l1 s- R1(config)#ip access-list ?& O! w" d3 f* w0 A. X
- extended Extended Access List
7 D3 l d4 V" N1 P - log-update Control access list log updates
7 @# D- u' C( z" |7 M4 ~7 P - logging Control access list logging
5 d, G9 |4 Y1 F! x( v0 I! ]8 O - resequence Resequence Access List& R- X Q r8 i2 Z ^) f
- standard Standard Access List( f' k" l( ^9 d
- % w' {& x* E7 T0 }
- R1(config)#ip access-list res? . C4 z" u$ X/ s8 {+ q0 W- C4 L
- resequence 7 p& D$ L, y; {4 O
6 m: s3 V! Q0 C; W; B7 g8 V8 L9 K- R1(config)#ip access-list res
4 B! W& k9 W. r( h% I( H/ R h3 p* z - R1(config)#ip access-list resequence ?* @& u4 R6 R' J0 o4 q$ I$ W
- <1-99> Standard IP access-list number
# y1 u; E$ E+ i/ a; Q - <100-199> Extended IP access-list number5 k& M3 W7 t, T* m1 |4 e9 _
- <1300-1999> Standard IP access-list number (expanded range)) g% R3 K, ~' w) z8 ^% p+ W% S& F
- <2000-2699> Extended IP access list number (expanded range)
) ]: g" q8 g; t1 }8 K* W9 e - WORD Access-list name4 t/ A; ?2 j @! p
+ _9 `/ O+ j( k2 t- R1(config)#ip access-list resequence super_user ?' O- L, r% Y9 w. f
- <1-2147483647> Starting Sequence Number
2 c: s3 l3 O# R3 l3 u X0 p" n# c4 J
; H. s3 J t2 M' C6 \& t: n! N! d- R1(config)#ip access-list resequence super_user 1 ?" V/ [8 K, {& c+ D9 p
- <1-2147483647> Step to increment the sequence number n, A* l# M, l5 V9 b
- " j9 j# d& F* q! z" E3 x) Z
- R1(config)#ip access-list resequence super_user 1 6
复制代码
6 ?1 y) B# @: M6 N% L: |+ S( [* D6 j; W+ p8 d
; _8 ]$ t0 t4 n( B
验证答案C,使用?进行提示,如果如下:
. n% e( Q& m+ M `( l4 m/ A# C& s: U! H Z- J+ q+ s! {
- R1(config)#ip access-list extended super_user
0 ?$ W( K: I! \& D& ? - R1(config-ext-nacl)#ip ?
! m9 D k3 p- Y( w. ~ - % Unrecognized command! \" D# h5 h, S/ @4 N
- R1(config-ext-nacl)#ip
复制代码 提示命令不正确了, ,虽然我直接将完整命令打上去,并没有提示有错误,命令也能执行,但是从上面的提示来看,考试要考的答案 应该不会是这个,至于为什么能执行这个命令,也许是我使用的模拟器的IOS版本较新吧。1 h5 ~8 ~2 u5 G7 J3 b$ R
9 Y3 t% n+ ]" X& g6 Y
8 S5 S; k+ Y3 A* M# o# G经过上面的分析,我认为本题的答案是 A
/ J5 D* C; m% }- o* h
# i9 }9 H0 ` r3 M) j+ D6 P0 d7 M3 O! H; R) ^
如果分析有误,欢迎各路大神批评指正。
S* P/ Z2 {/ ^, _
9 Z/ @, {' F& {' x" X7 E7 w. v |
72#
2019-4-24 16:07:24
回复(0)
收起回复
|