Cisco 10000-2P2-2DC Software Guide - Page 310

Applying a Time Range to a Numbered Access Control List, Example 12-2, Configuring a Time Range

Page 310 highlights

Time-Based ACLs Chapter 12 Configuring Traffic Filtering Example 12-2 creates a periodic time range named no-http that specifies Monday through Friday from 8:00 a.m. to 6:00 p.m. Example 12-2 Configuring a Time Range Router(config)# time-range no-http Router(config-time-range)# periodic weekdays 8:00 to 18:00 Example 12-3 creates a time range named HTTP that specifies both periodic and absolute values. During ACL processing, the router assumes that the time period begins right now because the absolute command does not specify a start value. The router then evaluates the periodic value, which indicates that the time period is restricted to Monday through Wednesday from 8:00 a.m. to 7:00 p.m. The time period ends on February 6 at 11:59 p.m. Example 12-3 Configuring a Time Range with Periodic and Absolute Entries Router(config)# time-range http Router(config-t-range)# periodic monday 8:00 to wednesday 19:00 Router(config-t-range)# absolute end 23:59 6 February 2000 Applying a Time Range to a Numbered Access Control List To apply a time range to the access control entries (ACEs) of a numbered extended access control list (ACL), enter the following commands beginning in global configuration mode: Step 1 Command Router (config)# access-list access-list-number [dynamic dynamic-name [timeout minutes]] {deny | permit} protocol source source-wildcard destination destination-wildcard [precedence precedence] [tos tos] [log | log-input] time-range time-range-name [fragments] Step 2 Step 3 Router(config)# interface type number slot/module/port.subinterface Router(config-if)# ip access-group {access-list-number | access-list-name} {in | out} Purpose Defines a numbered extended IP access control list (ACL). The time-range time-range-name argument specifies the name of the time range to apply to the ACE. Note In Cisco IOS Release 12.3(7)XI1, the time-range argument is required. For more information about the access-list command, see the Cisco IOS IP Command Reference, Volume 1 of 4: Addressing and Services, Release 12.3. Configures an interface and enters interface configuration mode. Controls access to an interface. Example 12-4 permits SMTP traffic to the access the mail host (128.88.1.2) on Monday through Sunday between the hours of 5:00 a.m. and 11:59 p.m, if the traffic belongs to an already established connection. The example creates the time range named smtp and applies it to the ACE of the extended access list numbered 102. The time-based ACL is then applied to the ingress serial 0 interface. 12-6 Cisco 10000 Series Router Software Configuration Guide OL-2226-23

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495
  • 496
  • 497
  • 498
  • 499
  • 500
  • 501
  • 502
  • 503
  • 504
  • 505
  • 506
  • 507
  • 508
  • 509
  • 510
  • 511
  • 512
  • 513
  • 514
  • 515
  • 516
  • 517
  • 518
  • 519
  • 520
  • 521
  • 522
  • 523
  • 524
  • 525
  • 526
  • 527
  • 528
  • 529
  • 530
  • 531
  • 532
  • 533
  • 534
  • 535
  • 536
  • 537
  • 538
  • 539
  • 540
  • 541
  • 542
  • 543
  • 544
  • 545
  • 546
  • 547
  • 548
  • 549
  • 550
  • 551
  • 552
  • 553
  • 554
  • 555
  • 556
  • 557
  • 558
  • 559
  • 560
  • 561
  • 562
  • 563
  • 564
  • 565
  • 566
  • 567
  • 568
  • 569
  • 570
  • 571
  • 572
  • 573
  • 574
  • 575
  • 576
  • 577
  • 578
  • 579
  • 580
  • 581
  • 582
  • 583
  • 584
  • 585
  • 586
  • 587
  • 588
  • 589
  • 590
  • 591
  • 592
  • 593
  • 594
  • 595
  • 596
  • 597
  • 598
  • 599
  • 600
  • 601
  • 602
  • 603
  • 604
  • 605
  • 606
  • 607
  • 608
  • 609
  • 610
  • 611
  • 612
  • 613
  • 614
  • 615
  • 616
  • 617
  • 618
  • 619
  • 620
  • 621
  • 622
  • 623
  • 624

12-6
Cisco 10000 Series Router Software Configuration Guide
OL-2226-23
Chapter 12
Configuring Traffic Filtering
Time-Based ACLs
Example 12-2
creates a periodic time range named
no-http
that specifies Monday through Friday from
8:00 a.m. to 6:00 p.m.
Example 12-2
Configuring a Time Range
Router(config)# time-range no-http
Router(config-time-range)# periodic weekdays 8:00 to 18:00
Example 12-3
creates a time range named
HTTP
that specifies both periodic and absolute values. During
ACL processing, the router assumes that the time period begins right now because the
absolute
command does not specify a
start
value. The router then evaluates the
periodic
value, which indicates
that the time period is restricted to Monday through Wednesday from 8:00 a.m. to 7:00 p.m. The time
period ends on February 6 at 11:59 p.m.
Example 12-3
Configuring a Time Range with Periodic and Absolute Entries
Router(config)# time-range http
Router(config-t-range)# periodic monday 8:00 to wednesday 19:00
Router(config-t-range)# absolute end 23:59 6 February 2000
Applying a Time Range to a Numbered Access Control List
To apply a time range to the access control entries (ACEs) of a numbered extended access control list
(ACL), enter the following commands beginning in global configuration mode:
Example 12-4
permits SMTP traffic to the access the mail host (128.88.1.2) on Monday through Sunday
between the hours of 5:00 a.m. and 11:59 p.m, if the traffic belongs to an already established connection.
The example creates the time range named
smtp
and applies it to the ACE of the extended access list
numbered 102. The time-based ACL is then applied to the ingress serial 0 interface.
Command
Purpose
Step 1
Router (config)#
access-list
access-list-number
[
dynamic
dynamic-name
[
timeout
minutes
]] {
deny
|
permit
}
protocol
source source-wildcard
destination destination-wildcard
[
precedence
precedence
] [
tos
tos
] [
log
|
log-input
]
time-range
time-range-name
[
fragments
]
Defines a numbered extended IP access control list (ACL).
The
time-range
time-range-name
argument specifies the name of
the time range to apply to the ACE.
Note
In Cisco IOS Release 12.3(7)XI1, the
time-range
argument is required.
For more information about the access-list command, see the
Cisco IOS IP Command Reference, Volume 1 of 4: Addressing and
Services, Release 12.3
.
Step 2
Router(config)#
interface
type
number
slot
/
module
/
port
.
subinterface
Configures an interface and enters interface configuration mode.
Step 3
Router(config-if)#
ip access-group
{
access-list-number
|
access-list-name
}
{
in
|
out
}
Controls access to an interface.