19-16
Catalyst 3550 Multilayer Switch Software Configuration Guide
78-11194-03
Chapter19 Configuring Network Security with ACLs
Configuring Router ACLs
and argument are referenced in the named and numbered extended ACL task tables in the previ ous
sections, the Creating Standard and Extended IP ACLs section on page 19-6, and the Creating Named
Standard and Extended ACLs section on page 19-14.
These are some of the many possible benefits of using time ranges:
You have more control over permitting or denying a user access to resources, such as an application
(identified by an IP address/mask pair and a port number).
You can control logging messages. ACL entries can log traffic at certain times of the day, but not
constantly. Therefore, you can simply deny access without needing to analyze many logs generate d
during peak hours.
Note The time range relies on the switch system clock. For this feature to work the way you intend, you
need a reliable clock source. We recommend that you use Network Time Protocol (NT P) to
synchronize the switch clock. For more information, see the Managin g the System Time and Date
section on page 6-32.
Beginning in privileged EXEC mode, follow these steps to c onf igur e a time -rang e pa rame ter f or a n
ACL:
To remove a configured time-range limitation, use the no time-range time-range-name global
configuration command.
Repeat the steps if you have multiple items that you want in effect at dif ferent times. This example sh ows
how to configure time ranges for workhours and for company holidays and how to verify your
configuration.
Switch(config)# time-range workhours
Switch(config-time-range)# periodic weekdays 8:00 to 12:00
Switch(config-time-range)# periodic weekdays 13:00 to 17:00
Switch(config-time-range)# exit
Switch(config)# time-range new_year_day_2000
Switch(config-time-range)# absolute start 00:00 1 Jan 2000 end 23:59 1 Jan 2000
Command Purpose
Step1 configure terminal Enter global configuration mode.
Step2 time-range time-range-name Identify the time-range by a meaningful name, and enter time-range
configuration mode. The name cannot contain a space or quotatio n mark
and must begin with a letter.
Step3 absolute [start time date]
[end time date]
or
periodic day-of-the-week hh:mm to
[day-of-the-week] hh:mm
or
periodic {weekdays | weekend | daily}
hh:mm to hh:mm
Specify when the function it will be applied to is in effect. Use some
combination of these commands; multiple periodic statements are
allowed; only one absolute statement is allowed. If more than one
absolute statement is configured, only the one configured last is
executed.
Step4 end Return to privileged EXEC mode.
Step5 show time-range Verify the time-range configuration.
Step6 copy running-config startup-config (Optional) Save your entries in the configuration file.