Chapter 26
Configuring Network Security with ACLs
Command
Step 3
absolute [start time date]
[end time date]
or
periodic day-of-the-week hh:mm to
[day-of-the-week] hh:mm
or
periodic {weekdays | weekend | daily}
hh:mm to hh:mm
Step 4
end
Step 5
show time-range
Step 6
copy running-config startup-config
Repeat the steps if you want multiple items in effect at different times. To remove a configured
time-range limitation, use the no time-range time-range-name global configuration command.
This example shows how to configure time ranges for workhours and to configure January 1, 2006 as a
company holiday and to verify your configuration.
Switch(config)# time-range workhours
Switch(config-time-range)# periodic weekdays 8:00 to 12:00
Switch(config-time-range)# periodic weekdays 13:00 to 17:00
Switch(config-time-range)# exit
Switch(config)# time-range new_year_day_2006
Switch(config-time-range)# absolute start 00:00 1 Jan 2006 end 23:59 1 Jan 2006
Switch(config-time-range)# end
Switch# show time-range
time-range entry: new_year_day_2003 (inactive)
time-range entry: workhours (inactive)
To apply a time-range, enter the time-range name in an extended ACL that can implement time ranges.
This example shows how to create and verify extended access list 188 that denies TCP traffic from any
source to any destination during the defined holiday times and permits all TCP traffic during work hours.
Switch(config)# access-list 188 deny tcp any any time-range new_year_day_2006
Switch(config)# access-list 188 permit tcp any any time-range workhours
Switch(config)# end
Switch# show access-lists
Extended IP access list 188
This example uses named ACLs to permit and deny the same traffic.
Switch(config)# ip access-list extended deny_access
Switch(config-ext-nacl)# deny tcp any any time-range new_year_day_2006
Switch(config-ext-nacl)# exit
Switch(config)# ip access-list extended may_access
Switch(config-ext-nacl)# permit tcp any any time-range workhours
Switch(config-ext-nacl)# end
Switch# show ip access-lists
Extended IP access list deny_access
Extended IP access list may_access
OL-23400-01
absolute start 00:00 01 January 2006 end 23:59 01 January 2006
periodic weekdays 8:00 to 12:00
periodic weekdays 13:00 to 17:00
10 deny tcp any any time-range new_year_day_2006 (inactive)
20 permit tcp any any time-range workhours (inactive)
10 deny tcp any any time-range new_year_day_2006 (inactive)
10 permit tcp any any time-range workhours (inactive)
Purpose
Specify when the function it will be applied to is operational.
You can use only one absolute statement in the time range. If you
•
configure more than one absolute statement, only the one configured
last is executed.
You can enter multiple periodic statements. For example, you could
•
configure different hours for weekdays and weekends.
See the example configurations.
Return to privileged EXEC mode.
Verify the time-range configuration.
(Optional) Save your entries in the configuration file.
Cisco ME 3800X and 3600X Switch Software Configuration Guide
Configuring IPv4 ACLs
26-17