在配置ACL规则时,要拒绝源IP地址为172.16.10.3的主机访问目的网段172.16.20.0/24的Web服务,应使用以下哪个命令()。
A
rule deny tcp source 172.16.10.3 0 destination 172.16.20.0 0.0.0.255 destination-port eq 80
B
rule deny tcp source 172.16.10.3 0 destination 172.16.20.0 0.0.0.255 source-port eq 80
C
rule deny udp source 172.16.10.3 0 destination 172.16.20.0 0.0.0.255 destination-port eq 80
D
rule deny icmp source 172.16.10.3 0 destination 172.16.20.0 0.0.0.255