Networking-Blog

My WordPress Blog

Cisco Time-Range QOS

This output shows an example of creating a time-based named ACL.
It denies HTTP traffic on Monday through Friday between the hours of 8:00 am and 6:00 pm
and allows UDP traffic on Saturday and Sunday from noon to 8:00 pm.

!
time-range no-http
periodic weekdays 8:00 to 18:00
!
time-range udp-yes
periodic weekend 12:00 to 20:00
!
ip access-list extended strict
permit tcp any any eq http time-range no-http
permit udp any any time-range udp-yes
!
!
Keep in mind there is an explicit deny at the end of the ACL. If you are going to permit ip any any
at the bottom of ACL, keep in mind that there has to be a deny entry for tcp HTTP traffic. This is because
when time-range no http ACL is in inactive state, it looks for a matching rule that will either permit or deny HTTP traffic
.
!
Example of using a time-based ACL in QoS Policy:
!
class-map Traffic_Class
match access-group strict
!
policy-map QoS-Policy
class Traffic_Class
priority 500
class class-default
fair-queue

Cisco Time-Range

An extended access control list can be either a numbered or a named ACL. In each case,
the Time-Range option is added to provide an additional qualifier for the permit|deny statement.

Time-Range command

The following time range example with a periodic statement denies web traffic to employees on the
Ethernet LAN for Monday through Friday during business hours (8:00 A.M. to 6:00 P.M.).

time-range no-web
periodic weekdays 8:00 to 18:00
!
ip access-list extended block-web
deny tcp any any eq www time-range no-web
permit ip any any
!
interface ethernet 0
ip access-group block-web in
!

The following example uses a time-based access list to allow a LAN to begin accessing the network
beginning at 8:00 A.M. on January 1, 2003. The access will continue until stopped.
The access list and time range together permit traffic on Ethernet interface 0 starting.

time-range new-lan
absolute start 8:00 1 January 2003
!
ip access-list extended start-service
permit ip 192.168.15.0 0.0.0.255 any time-range new-lan
!
interface ethernet 0
ip access-group start-service in

The following example uses a time-based access list to block a LAN from accessing the
network beginning at midnight on December 31, 2003
.

time-range stop-lan
absolute end 23:59 31 December 2003
!
ip access-list extended stop-service
permit ip 192.168.15.0 0.0.0.255 any time-range stop-lan
!
interface ethernet 0
ip access-group stop-service in

The following example uses a time-based access list to permit weekend employees to browse
the Internet for a two month test period from 8:00 A.M. on June 1, 2003, to 6:00 P.M.on July 31, 2003.

time-range web-test
absolute start 8:00 1 June 2003 end 18:00 31 July 2003
periodic weekends 00:00 to 23:59
!
ip access-list extended lan-web
permit tcp 192.168.15.0 0.0.0.255 any eq www time-range web-test
!
interface ethernet 0
ip access-group lan-web in

The following time range example with a periodic statement allows access to web traffic access
to employees on the Ethernet LAN for Monday through Friday during business hours
(8:00 A.M. to 4:00 P.M.).

time-range Workhours
periodic weekdays 8:00 to 16:00
!
ip access-list extended permit Permission-To-Internal-Server-In-Work-Hours
permit tcp any host 10.0.0.5 eq www time-range Workhours
deny tcp any host 10.0.0.5 eq www
permit ip any any
!
interface ethernet 0
ip access-group Permission-To-Internal-Server-In-Work-Hours in

The following time range example with a periodic statement allows web traffic
to www.facebook.com to employees on the Ethernet LAN for Monday through Friday
during non business hours (17:00 P.M. to 22:00 P.M.)

time-range FACEBOOK_TIME
periodic weekdays 17:00 to 22:00
!
ip access-list extended FACEBOOK_TIME
remark WWW.FACEBOOK.COM
permit tcp 192.168.3.0 0.0.0.7 66.220.144.0 0.0.15.255 eq www time-range FACEBOOK_TIME
permit tcp 192.168.3.0 0.0.0.7 66.220.144.0 0.0.15.255 eq 443 time-range FACEBOOK_TIME
deny tcp 192.168.3.0 0.0.0.7 66.220.144.0 0.0.15.255 eq www
deny tcp 192.168.3.0 0.0.0.7 66.220.144.0 0.0.15.255 eq 443
remark FACEBOOK.COM
permit tcp 192.168.3.0 0.0.0.7 69.63.176.0 0.0.15.255 eq www time-range FACEBOOK_TIME
permit tcp 192.168.3.0 0.0.0.7 69.63.176.0 0.0.15.255 eq 443 time-range FACEBOOK_TIME
deny tcp 192.168.3.0 0.0.0.7 69.63.176.0 0.0.15.255 eq www
deny tcp 192.168.3.0 0.0.0.7 69.63.176.0 0.0.15.255 eq 443
remark HTTP
permit tcp 192.168.3.0 0.0.0.7 any eq www
remark HTTPS
permit tcp 192.168.3.0 0.0.0.7 any eq 443
remark DENY_TRAFFIC
deny   ip any any log
!
interface ethernet 0
ip access-group FACEBOOK_TIME in
!
!
Keep in mind there is an explicit deny at the end of the ACL. If you are going to permit ip any any
at the bottom of ACL, keep in mind that there has to be a deny entry for tcp HTTP traffic. This is because
when
time-range FACEBOOK_TIME ACL is in inactive state, it looks for a matching rule that will either permit or deny FACEBOOK_TIME HTTP traffic.