An extended access control list can be either a numbered or a named ACL. In each case,
the Time-Range option is added to provide an additional qualifier for the permit|deny statement.
Time-Range command
The following time range example with a periodic statement denies web traffic to employees on the
Ethernet LAN for Monday through Friday during business hours (8:00 A.M. to 6:00 P.M.).
time-range no-web
periodic weekdays 8:00 to 18:00
!
ip access-list extended block-web
deny tcp any any eq www time-range no-web
permit ip any any
!
interface ethernet 0
ip access-group block-web in
!
The following example uses a time-based access list to allow a LAN to begin accessing the network
beginning at 8:00 A.M. on January 1, 2003. The access will continue until stopped.
The access list and time range together permit traffic on Ethernet interface 0 starting.
time-range new-lan
absolute start 8:00 1 January 2003
!
ip access-list extended start-service
permit ip 192.168.15.0 0.0.0.255 any time-range new-lan
!
interface ethernet 0
ip access-group start-service in
The following example uses a time-based access list to block a LAN from accessing the
network beginning at midnight on December 31, 2003.
time-range stop-lan
absolute end 23:59 31 December 2003
!
ip access-list extended stop-service
permit ip 192.168.15.0 0.0.0.255 any time-range stop-lan
!
interface ethernet 0
ip access-group stop-service in
The following example uses a time-based access list to permit weekend employees to browse
the Internet for a two month test period from 8:00 A.M. on June 1, 2003, to 6:00 P.M.on July 31, 2003.
time-range web-test
absolute start 8:00 1 June 2003 end 18:00 31 July 2003
periodic weekends 00:00 to 23:59
!
ip access-list extended lan-web
permit tcp 192.168.15.0 0.0.0.255 any eq www time-range web-test
!
interface ethernet 0
ip access-group lan-web in
The following time range example with a periodic statement allows access to web traffic access
to employees on the Ethernet LAN for Monday through Friday during business hours
(8:00 A.M. to 4:00 P.M.).
time-range Workhours
periodic weekdays 8:00 to 16:00
!
ip access-list extended permit Permission-To-Internal-Server-In-Work-Hours
permit tcp any host 10.0.0.5 eq www time-range Workhours
deny tcp any host 10.0.0.5 eq www
permit ip any any
!
interface ethernet 0
ip access-group Permission-To-Internal-Server-In-Work-Hours in
The following time range example with a periodic statement allows web traffic
to www.facebook.com to employees on the Ethernet LAN for Monday through Friday
during non business hours (17:00 P.M. to 22:00 P.M.)
time-range FACEBOOK_TIME
periodic weekdays 17:00 to 22:00
!
ip access-list extended FACEBOOK_TIME
remark WWW.FACEBOOK.COM
permit tcp 192.168.3.0 0.0.0.7 66.220.144.0 0.0.15.255 eq www time-range FACEBOOK_TIME
permit tcp 192.168.3.0 0.0.0.7 66.220.144.0 0.0.15.255 eq 443 time-range FACEBOOK_TIME
deny tcp 192.168.3.0 0.0.0.7 66.220.144.0 0.0.15.255 eq www
deny tcp 192.168.3.0 0.0.0.7 66.220.144.0 0.0.15.255 eq 443
remark FACEBOOK.COM
permit tcp 192.168.3.0 0.0.0.7 69.63.176.0 0.0.15.255 eq www time-range FACEBOOK_TIME
permit tcp 192.168.3.0 0.0.0.7 69.63.176.0 0.0.15.255 eq 443 time-range FACEBOOK_TIME
deny tcp 192.168.3.0 0.0.0.7 69.63.176.0 0.0.15.255 eq www
deny tcp 192.168.3.0 0.0.0.7 69.63.176.0 0.0.15.255 eq 443
remark HTTP
permit tcp 192.168.3.0 0.0.0.7 any eq www
remark HTTPS
permit tcp 192.168.3.0 0.0.0.7 any eq 443
remark DENY_TRAFFIC
deny ip any any log
!
interface ethernet 0
ip access-group FACEBOOK_TIME in
!
!
Keep in mind there is an explicit deny at the end of the ACL. If you are going to permit ip any any
at the bottom of ACL, keep in mind that there has to be a deny entry for tcp HTTP traffic. This is because
when time-range FACEBOOK_TIME ACL is in inactive state, it looks for a matching rule that will either permit or deny FACEBOOK_TIME HTTP traffic.
Comments
(There are currently no comments for this post.)