Creating Time Range Objects
If you want a policy to apply only during a specified time range, create a time range object, then specify that object in the policy. Note that this object works on threat defense devices only.
You can specify time range objects only in policy types listed at the bottom of this topic.
Note | The timezone represents the device's local time and is used ONLY for applying the time ranges in rules in the policies that support the time ranges. The timezone does not change the configured time of the device. To verify the configuration, in the threat defense CLI, use the show time-range timezone and show time commands (see the Cisco Secure Firewall Threat Defense Command Reference guide). In addition, the timezone of a chassis overrides the management center timezone. |
Before you begin
Time ranges are applied based on the time zone associated with the device that processes the traffic. By default, this is UTC. To change the time zone associated with a device, go to Device > Platform Settings.
Procedure
Step 1 | Choose Objects > Object Management. |
Step 2 | Choose Time Range from the list of object types. |
Step 3 | Click Add Time Range. |
Step 4 | Enter values. Observe the following guidelines:
|
Step 5 | Click Save. |
What to do next
Configure time ranges in any of the following:
-
Access control rules
-
Prefilter rules
-
Tunnel rules
-
VPN group policy
In a VPN group policy object, specify the time range object using the Access Hours field. For details, see Configure Group Policy Objects and Group Policy Advanced Options.