Users Guide

Access Control Lists 677
A named time range can contain up to 10 configured time ranges. Only one
absolute time range can be configured per time range. During the ACL
configuration, a configured time range can be associated with the ACL to
provide additional control over permitting or denying a user access to network
resources.
Benefits of using time-based ACLs include:
Providing more control over permitting or denying a user access to
resources, such as an application (identified by an IP address/mask pair and
a port number).
Providing control of logging messages. Individual ACL rules defined within
an ACL can be set to log traffic only at certain times of the day so access
can simply be denied without the need to analyze many logs generated
during peak hours.
ACL Limitations
There are two hardware matching engines visible to the Dell switch
administrator: the ingress processor and the egress processor. Each of these
processors has different limits and actions. The ingress matching engine
processes packets on ingress to the switch and can apply actions such as
applying CoS processing, diverting to a different port, etc. The egress
matching engine processes packets after they are switched and queued for
egress and supports policies such as rewriting the DSCP or CoS values, as well
as the normal permit (forward) and deny (drop) actions.
ACLs operate by matching on specific fields within packets. Various match
conditions (operators) are supported (e.g., equal, less than, not equal, etc.),
along with masks that support selection of all or a portion of a field. Each field
to be matched is assigned to a matching engine (a slice). A slice is defined by
an offset into the packet that is compared against a set of matching values
and masks along with an associated action (ACEs). Each Dell EMC
Networking N-Series switch supports a fixed number of slices and each slice
NOTE: Adding a conflicting periodic time range to an absolute time range will
cause the time range to become inactive. For example, consider an absolute time
range from 8:00 AM Tuesday March 1st 2011 to 10 PM Tuesday March 1st 2011.
Adding a periodic entry using the 'weekend' keyword will cause the time-range
to become inactive because Tuesdays are not on the weekend.