7-9
Cisco ASA Series Firewall ASDM Configuration Guide
Chapter7 Configuring Access Rules
Guidelines and Limitations
Step9 Select the service type.
Step10 (Optional) To add a time range to your access rule that specifies when traffic can be allowed or denied,
click More Options to expand the list.
a. To the right of the Time Range drop down list, click the browse button.
The Browse Time Range dialog box appears.
b. Click Add.
The Add Time Range dialog box appears.
c. In the Time Range Name field, enter a time range name, with no spaces.
d. Choose the Start Time and the End Time.
e. To specify additional time constraints for the time range, such as specifying the days of the week or
the recurring weekly interval in which the time range will be active, click Add, and choose the
specifications.
f. Click OK to apply the optional time range specifications.
Step11 (Optional) In the Description field, add a text description about the access rule.
The description can contain multiple lines; however, each line can be no more than 100 characters in
length.
Step12 (Optional) Logging is enabled by default. You can disable logging by unchecking the check box, or you
can change the logging level from the drop-down list. The default logging level is Informational.
Step13 Click OK. The access rule appears with the newly configured access rules.
Step14 Click Apply to save the access rule to your configuration.
You can edit or delete a particular access rule by selecting the rule and then clicking Edit or Delete.
Adding an EtherType Rule (Transparent Mode Only)
The EtherType Rules window shows access rules based on packet EtherTypes. EtherType rules are used
to configure non-IP related traffic policies through the ASA when operating in transparent mode. In
transparent mode, you can apply both extended and EtherType access rules to an interface. EtherType
rules take precedence over the extended access rules.
For more information about EtherType rules, see the “Information About Access Rules” section on
page 7-1.
To add an EtherType rule, perform the following steps:
Step1 Choose Configuration > Device Management > Management Access > EtherType Rules.
Step2 Click Add.
The Add EtherType rules window appears.
Step3 (Optional) To specify the placement of the new EtherType rule, select an existing rule, and click Insert...
to add the EtherType rule before the selected rule, or click Insert After... to add the EtherType rule after
the selected rule.
Step4 From the Interface drop-down list, choose the interface on which to apply the rule. Choose Any to apply
a global rule.