Skip navigation
Cisco Learning Home > CCNP Security Study Group > Discussions
746 Views 4 Replies Latest reply: Mar 21, 2012 3:33 AM by Cristian RSS

Currently Being Moderated

Time based ACLs

Mar 20, 2012 10:21 AM

ericleahy - CCNP, CCDP, CCNA SEC 206 posts since
Jan 8, 2010

Hi guys,

 

This is a nice quick one, which I think I already know the answer to. How many time-range ACL's can be applied to the same access list, to the same host, in the same traffic direction?  Example;

 

time-range UPDATES_DECEMBER_15

absolute start 12:00 15 December 2012 end 14:00 15 December 2012

!

time-rangeUPDATES_DECEMBER_22

absolute start 12:00 22 December 2012 end 14:00 22 December 2012

 

access-list MATCH-WEB-TRAFFFIC extended deny tcp host 192.168.10.10 any eq www time-range UPDATES_DECEMBER_15

access-list MATCH-WEB-TRAFFFIC extended deny tcp host 192.168.10.10 any eq www time-range UPDATES_DECEMBER_22

 

My feeling after many hours of testing is you can only have one?

 

Thanks guys

 

Eric

  • Fabio - CCNA Security 83 posts since
    Aug 4, 2008
    Currently Being Moderated
    Re: Time based ACLs

    yes, just one

     

    try with

    time-range XXXXX

       periodic xxx xxxx xxxx

     

     

    fabio

  • Cristian 36 posts since
    Jan 3, 2011
    Currently Being Moderated
    Re: Time based ACLs

    Interesting kind of doubt!

     

    Copying exactly from the "Time-Based Access Lists using time ranges", consider that:

     

     

    If a time-range command has both absolute and periodic values specified, then the periodic items

    are evaluated only after the absolute start time is reached, and are not further evaluated after the

    absolute end time is reached.

     

     

     

    I am then pretty sure that the periodic time range validity occurs inside the absolute time range validity, in a logical AND fashion. To be clear:

     

     

    ABSOLUTE:     START                                                          END

                                |------------------------------------------------------------------|

     

    PERIODIC:                  |--------|      |---------|      |---------|     |---------|  

     

     

    RESULTS:                  |--------|      |---------|      |---------|     |---------|    

     

     

    Do tou agree?

     

     

    Doc link:   http://www.cisco.com/en/US/docs/ios/12_0t/12_0t1/feature/guide/timerang.pdf

     

     

     

    Cristian

Actions

More Like This

  • Retrieving data ...

Bookmarked By (0)