A network engineer is testing an automation platform that interacts with Cisco networking devices via NETCONF over SSH. In accordance with internal security requirements: - NETCONF sessions are permitted only from trusted sources in the 172.16.20.0/24 subnet. - CLI SSH access is permitted from any source. Which configuration must the engineer apply on R1?