Create a time range object
Establish a time range object so policies apply only during specified periods, enabling precise control of network traffic.
If you want a policy to apply only during a specified time range, create a time range object and specify that object in the policy. This object works on Firewall Threat Defense devices only.
You can specify time range objects only in certain policy types, which are listed in this topic.
Note | The timezone represents the device's local time and is used only for applying the time ranges in rules in the policies that support the time ranges. The timezone does not change the configured time of the device. To verify the configuration, in the Firewall Threat Defense CLI, use the show time-range timezone and show time commands (see the Cisco Secure Firewall Threat Defense Command Reference guide). In addition, the timezone of a chassis overrides the management center timezone. |
Before you begin
Time ranges operate based on the time zone associated with the device that processes the traffic. By default, this is UTC. To change the time zone associated with a device, go to .
Procedure
Step 1 | Choose from the list of object types. |
Step 2 | Click Add Time Range. |
Step 3 | Enter the object name and specify the desired time periods.
|
Step 4 | Click Save. |
What to do next
Configure time ranges in any of these:
-
Access control rules
-
Prefilter rules
-
Tunnel rules
-
VPN group policy
In a VPN group policy object, specify the time range object using the Access Hours field. For details, see Configure a group policy object and Advanced group policy option fields and values.