<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Manage PIX ACLs ? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/manage-pix-acls/m-p/790654#M1004924</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do a "sh access-list" from enable mode you should see the hit count at the end of the line eg: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list from_prod1 line 1 permit tcp object-group prod_machines host 10.228.56.2 eq telnet&lt;/P&gt;&lt;P&gt;access-list from_prod1 line 1 permit tcp host 10.228.51.51 host 10.228.56.2 eq telnet (hitcnt=12)&lt;/P&gt;&lt;P&gt;access-list from_prod1 line 1 permit tcp host 10.230.24.77 host 10.228.56.2 eq telnet (hitcnt=0)&lt;/P&gt;&lt;P&gt;access-list from_prod1 line 1 permit tcp host 10.181.66.12 host 10.228.56.2 eq telnet (hitcnt=0)&lt;/P&gt;&lt;P&gt;access-list from_prod1 line 1 permit tcp host 10.228.50.95 host 10.228.56.2 eq telnet (hitcnt=0)&lt;/P&gt;&lt;P&gt;access-list from_prod1 line 2 permit tcp object-group prod_machines host 10.228.56.3 eq telnet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So only the first line in the above access-list has any hits. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can reset the counters by using the &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"clear access-list &lt;ACCESS-LIST name=""&gt; counters" &lt;/ACCESS-LIST&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 10 May 2007 08:47:00 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2007-05-10T08:47:00Z</dc:date>
    <item>
      <title>Manage PIX ACLs ?</title>
      <link>https://community.cisco.com/t5/network-security/manage-pix-acls/m-p/790653#M1004923</link>
      <description>&lt;P&gt;Hello all, &lt;/P&gt;&lt;P&gt;i have a lot of rule on my V7.0 PIX and i want to know if there is a way to find an used rules in order to reduce the number of rules or maybe to know last time rules have been used or matched ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:11:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/manage-pix-acls/m-p/790653#M1004923</guid>
      <dc:creator>yann.boulet</dc:creator>
      <dc:date>2019-03-11T10:11:46Z</dc:date>
    </item>
    <item>
      <title>Re: Manage PIX ACLs ?</title>
      <link>https://community.cisco.com/t5/network-security/manage-pix-acls/m-p/790654#M1004924</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do a "sh access-list" from enable mode you should see the hit count at the end of the line eg: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list from_prod1 line 1 permit tcp object-group prod_machines host 10.228.56.2 eq telnet&lt;/P&gt;&lt;P&gt;access-list from_prod1 line 1 permit tcp host 10.228.51.51 host 10.228.56.2 eq telnet (hitcnt=12)&lt;/P&gt;&lt;P&gt;access-list from_prod1 line 1 permit tcp host 10.230.24.77 host 10.228.56.2 eq telnet (hitcnt=0)&lt;/P&gt;&lt;P&gt;access-list from_prod1 line 1 permit tcp host 10.181.66.12 host 10.228.56.2 eq telnet (hitcnt=0)&lt;/P&gt;&lt;P&gt;access-list from_prod1 line 1 permit tcp host 10.228.50.95 host 10.228.56.2 eq telnet (hitcnt=0)&lt;/P&gt;&lt;P&gt;access-list from_prod1 line 2 permit tcp object-group prod_machines host 10.228.56.3 eq telnet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So only the first line in the above access-list has any hits. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can reset the counters by using the &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"clear access-list &lt;ACCESS-LIST name=""&gt; counters" &lt;/ACCESS-LIST&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2007 08:47:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/manage-pix-acls/m-p/790654#M1004924</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-05-10T08:47:00Z</dc:date>
    </item>
    <item>
      <title>Re: Manage PIX ACLs ?</title>
      <link>https://community.cisco.com/t5/network-security/manage-pix-acls/m-p/790655#M1004925</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your help, just another question, do you know if it's possible to transform names in the configuration to ip addresses, i don't remember how to do it it's just be sure of the ip addresses when i use "sh access-list"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2007 10:33:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/manage-pix-acls/m-p/790655#M1004925</guid>
      <dc:creator>yann.boulet</dc:creator>
      <dc:date>2007-05-10T10:33:52Z</dc:date>
    </item>
    <item>
      <title>Re: Manage PIX ACLs ?</title>
      <link>https://community.cisco.com/t5/network-security/manage-pix-acls/m-p/790656#M1004926</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i understand correctly i'm not sure you can do this. You can do a "sh names" and then cross reference with the access-list but i don't know of a way to transpose the ip address instead of the name in a "sh access-list" &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope i haven't misunderstood. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2007 10:40:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/manage-pix-acls/m-p/790656#M1004926</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-05-10T10:40:23Z</dc:date>
    </item>
    <item>
      <title>Re: Manage PIX ACLs ?</title>
      <link>https://community.cisco.com/t5/network-security/manage-pix-acls/m-p/790657#M1004927</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There should be an entry in your configureation&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"names"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if you run the command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"no names"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then all address to name translations will be turned off. This will *not* remove the name entries so you can turn it back on again without a problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;** Please rate posts if helpful **&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2007 11:17:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/manage-pix-acls/m-p/790657#M1004927</guid>
      <dc:creator>mark.j.hodge</dc:creator>
      <dc:date>2007-05-10T11:17:00Z</dc:date>
    </item>
    <item>
      <title>Re: Manage PIX ACLs ?</title>
      <link>https://community.cisco.com/t5/network-security/manage-pix-acls/m-p/790658#M1004928</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This might be more useful if you do a `sh access-list | i hitcnt=0'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That way you can sort out the rules that haven't received any hits over a certain time fram.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2007 13:45:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/manage-pix-acls/m-p/790658#M1004928</guid>
      <dc:creator>laurent.geyer</dc:creator>
      <dc:date>2007-05-10T13:45:49Z</dc:date>
    </item>
  </channel>
</rss>

