A time-based ACL has been configured on a router. Using the show access-list command, you notice that the ACL entry associated to the time range is currently inactive. What could be the cause?
- The ACL is not applied to an interface.
- The time range specified is outside the router’s current internal clock time.
- The router is unable to reach the NTP server.
- The time range has not been configured.
Explanation: A time-based ACL entry relies on the router's system clock to determine its validity. If the show access-list command indicates that an entry is inactive, it means the current time on the router's internal clock does not fall within the specific time range defined for that ACL entry. While NTP is often used to synchronize the clock, the immediate cause of the "inactive" status is the time mismatch itself.
Related exam: Checkpoint Exam: MPLS and VPN Technologies
