Cisco IOS Time Based Access-List

You might also like

Download as pdf or txt
Download as pdf or txt
You are on page 1of 5

Cisco IOS Time Based Access-List | NetworkLessons.com https://networklessons.com/cisco/ccna-routing-switching/cisco-ios-tim...

1 of 5 8.7.2016 12:05
Cisco IOS Time Based Access-List | NetworkLessons.com https://networklessons.com/cisco/ccna-routing-switching/cisco-ios-tim...

R2#clock set 12:48:00 14 July 2015

R2(config)#time-range WORK_HOURS
R2(config-time-range)#periodic ?
Friday Friday
Monday Monday
Saturday Saturday
Sunday Sunday
Thursday Thursday
Tuesday Tuesday
Wednesday Wednesday
daily Every day of the week
weekdays Monday thru Friday
weekend Saturday and Sunday

R2(config-time-range)#periodic weekdays 09:00 to 17:00

R2(config)#ip access-list extended NO_FACEBOOK


R2(config-ext-nacl)#deny tcp any host 192.168.23.3 eq 80 time-range
WORK_HOURS
R2(config-ext-nacl)#permit ip any any

2 of 5 8.7.2016 12:05
Cisco IOS Time Based Access-List | NetworkLessons.com https://networklessons.com/cisco/ccna-routing-switching/cisco-ios-tim...

R2(config)#interface FastEthernet 0/0


R2(config-if)#ip access-group NO_FACEBOOK in

R1#telnet 192.168.23.3 80
Trying 192.168.23.3, 80 ...
% Destination unreachable; gateway or host down

R2#show access-lists
Extended IP access list NO_FACEBOOK
10 deny tcp any host 192.168.23.3 eq www time-range WORK_HOURS
(active) (3 matches)
20 permit ip any any

R2#clock set 21:00:00 14 July 2015

R1#telnet 192.168.23.3 80
Trying 192.168.23.3, 80 ... Open

R2#show access-lists
Extended IP access list NO_FACEBOOK
10 deny tcp any host 192.168.23.3 eq www time-range WORK_HOURS
(inactive) (3 matches)
20 permit ip any any (4 matches)

3 of 5 8.7.2016 12:05
Cisco IOS Time Based Access-List | NetworkLessons.com https://networklessons.com/cisco/ccna-routing-switching/cisco-ios-tim...

20 permit ip any any (4 matches)

hostname R1
!
interface FastEthernet 0/0
ip address 192.168.12.1 255.255.255.0
!
ip route 192.168.23.0 255.255.255.0 192.168.12.2
!
end

hostname R2
!
interface FastEthernet 0/0
ip address 192.168.12.2 255 255.255.0
ip access-group NO_FACEBOOK in
!
interface FastEthernet 0/1
ip address 192.168.23.2 255 255.255.0
ip access-group NO_FACEBOOK in
!
time-range WORK_HOURS
periodic weekdays 09:00 to 17:00
!
ip access-list extended NO_FACEBOOK
deny tcp any host 192.168.23.3 eq 80 time-range WORK_HOURS
permit ip any any
!
end

4 of 5 8.7.2016 12:05
Cisco IOS Time Based Access-List | NetworkLessons.com https://networklessons.com/cisco/ccna-routing-switching/cisco-ios-tim...

end

hostname R3
!
interface FastEthernet 0/0
ip address 192.168.23.3 255.255.255.0
!
ip route 192.168.12.0 255.255.255.0 192.168.23.2
!
end

5 of 5 8.7.2016 12:05

You might also like