<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Firewall Rule Time Based in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-firewall-rule-time-based/m-p/996224#M916493</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What do you mean by this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"I tried to put the rule in but it wiped out the default rules so I reverted it real fast."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 18 Jul 2008 12:07:39 GMT</pubDate>
    <dc:creator>Farrukh Haroon</dc:creator>
    <dc:date>2008-07-18T12:07:39Z</dc:date>
    <item>
      <title>ASA Firewall Rule Time Based</title>
      <link>https://community.cisco.com/t5/network-security/asa-firewall-rule-time-based/m-p/996222#M916481</link>
      <description>&lt;P&gt;I am looking to block internet access for some of our hosts during specific time periods. I would like to block it by IP since I can make sure they always get the same IP with DHCP reservations. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to put the rule in but it wiped out the default rules so I reverted it real fast. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any help or guidance on this.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:16:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firewall-rule-time-based/m-p/996222#M916481</guid>
      <dc:creator>robertgile1</dc:creator>
      <dc:date>2019-03-11T13:16:25Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Firewall Rule Time Based</title>
      <link>https://community.cisco.com/t5/network-security/asa-firewall-rule-time-based/m-p/996223#M916485</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Suppose youwant to block WEB access for IP x.x.x.x from 9am to 6pm on weekdays.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- first create a time-range&lt;/P&gt;&lt;P&gt;myPix(config)#time-range biz_time&lt;/P&gt;&lt;P&gt;myPIX(config-time-range)#periodic weekdays 09:00 to 18:00&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- then use the time-range in the access-list&lt;/P&gt;&lt;P&gt;- Suppose your existing access-list on the inside interface is 101, then&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 101 line 1 deny tcp host x.x.x.x any eq 80 time-range biz_time&lt;/P&gt;&lt;P&gt;access-list 101 line 2 deny tcp host x.x.x.x any eq 443 time-range biz_time&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jul 2008 04:07:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firewall-rule-time-based/m-p/996223#M916485</guid>
      <dc:creator>dhananjoy chowdhury</dc:creator>
      <dc:date>2008-07-18T04:07:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Firewall Rule Time Based</title>
      <link>https://community.cisco.com/t5/network-security/asa-firewall-rule-time-based/m-p/996224#M916493</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What do you mean by this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"I tried to put the rule in but it wiped out the default rules so I reverted it real fast."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jul 2008 12:07:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firewall-rule-time-based/m-p/996224#M916493</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-07-18T12:07:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Firewall Rule Time Based</title>
      <link>https://community.cisco.com/t5/network-security/asa-firewall-rule-time-based/m-p/996225#M916500</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was using the ASDM and as soon as I put a rule on the inside interface, it wiped out the default rules to allow outbound traffic. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jul 2008 12:15:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firewall-rule-time-based/m-p/996225#M916500</guid>
      <dc:creator>robertgile1</dc:creator>
      <dc:date>2008-07-18T12:15:20Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Firewall Rule Time Based</title>
      <link>https://community.cisco.com/t5/network-security/asa-firewall-rule-time-based/m-p/996226#M916510</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'll give this a try this weekend. Now I would apply this on my inside interface, right?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jul 2008 12:16:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firewall-rule-time-based/m-p/996226#M916510</guid>
      <dc:creator>robertgile1</dc:creator>
      <dc:date>2008-07-18T12:16:19Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Firewall Rule Time Based</title>
      <link>https://community.cisco.com/t5/network-security/asa-firewall-rule-time-based/m-p/996227#M916516</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is OK, by default all 'higher' to 'lower' security communication is enabled. But once you apply your own ACL that rule goes away (as now your applied ACL has implicit deny ip any any at the end). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jul 2008 13:09:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firewall-rule-time-based/m-p/996227#M916516</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-07-18T13:09:37Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Firewall Rule Time Based</title>
      <link>https://community.cisco.com/t5/network-security/asa-firewall-rule-time-based/m-p/996228#M916522</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So I will have to explicitly permit other traffic out right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;something like this: [just free hand and in no way meant to be actual commands]&lt;/P&gt;&lt;P&gt;access-list 100&lt;/P&gt;&lt;P&gt;deny 192.168.0.10 based on this_time_rule&lt;/P&gt;&lt;P&gt;permit any to any less secure network&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jul 2008 13:36:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firewall-rule-time-based/m-p/996228#M916522</guid>
      <dc:creator>robertgile1</dc:creator>
      <dc:date>2008-07-18T13:36:05Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Firewall Rule Time Based</title>
      <link>https://community.cisco.com/t5/network-security/asa-firewall-rule-time-based/m-p/996229#M916527</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes robert, once you 'Deny' the undesired flows, you have to permit the rest.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perhaps a better approach would be:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;deny 192.168.0.10 based on this_time_rule &lt;/P&gt;&lt;P&gt;permit ip &lt;LAN subnet=""&gt; any&lt;/LAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jul 2008 14:15:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firewall-rule-time-based/m-p/996229#M916527</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-07-18T14:15:18Z</dc:date>
    </item>
  </channel>
</rss>

