<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Ronaldo,You could use the  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/delete-unused-object-groups/m-p/2768250#M177686</link>
    <description>&lt;P&gt;Hi Ronaldo,&lt;/P&gt;&lt;P&gt;You could use the 'show access-list' output and see if there is hit counts. whichever is not having you could remove that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Akshay Rastogi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 15 Oct 2015 18:14:32 GMT</pubDate>
    <dc:creator>Akshay Rastogi</dc:creator>
    <dc:date>2015-10-15T18:14:32Z</dc:date>
    <item>
      <title>Delete unused object-groups</title>
      <link>https://community.cisco.com/t5/network-security/delete-unused-object-groups/m-p/2768249#M177685</link>
      <description>&lt;P&gt;Hello Community!&lt;/P&gt;&lt;P&gt;I would like to clean up an old ASA (5520) which is still in production, so I cannot just wipe the config and start over and I was wondering if there is way to know which object groups are being used and which are not (so I can delete them).&lt;/P&gt;&lt;P&gt;When it comes to ACL, I will uses Notepadd++ and an &lt;A href="http://docs.notepad-plus-plus.org/index.php?title=User_Defined_Language_Files" target="_blank"&gt;User Defined Language&lt;/A&gt; to help me with the reading.&lt;/P&gt;&lt;P&gt;I know that it is going to take time but I want to do it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; if you have any suggestions or additional tools that can help me I want to hear about them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;Rolando Valenzuela.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:45:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/delete-unused-object-groups/m-p/2768249#M177685</guid>
      <dc:creator>Rolando Valenzuela</dc:creator>
      <dc:date>2019-03-12T06:45:17Z</dc:date>
    </item>
    <item>
      <title>Hi Ronaldo,You could use the</title>
      <link>https://community.cisco.com/t5/network-security/delete-unused-object-groups/m-p/2768250#M177686</link>
      <description>&lt;P&gt;Hi Ronaldo,&lt;/P&gt;&lt;P&gt;You could use the 'show access-list' output and see if there is hit counts. whichever is not having you could remove that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Akshay Rastogi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2015 18:14:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/delete-unused-object-groups/m-p/2768250#M177686</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-10-15T18:14:32Z</dc:date>
    </item>
    <item>
      <title>I think about that, but I</title>
      <link>https://community.cisco.com/t5/network-security/delete-unused-object-groups/m-p/2768251#M177687</link>
      <description>&lt;P&gt;I think about that, but I would like a easier way to do it hahahahah since the FW has like 100+ object group and each ACL is more than 300 lines.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The other idea I came with, is that I can make a list of all the object-groups that are in all the ACLs and check which object groups are not in the ACL, at least is a start!&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2015 19:09:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/delete-unused-object-groups/m-p/2768251#M177687</guid>
      <dc:creator>Rolando Valenzuela</dc:creator>
      <dc:date>2015-10-15T19:09:21Z</dc:date>
    </item>
    <item>
      <title>Hi Rolando,In any case if</title>
      <link>https://community.cisco.com/t5/network-security/delete-unused-object-groups/m-p/2768252#M177688</link>
      <description>&lt;P&gt;Hi Rolando,&lt;/P&gt;&lt;P&gt;In any case if this any of the object-group in any acl gets a hit then you are not gonna remove that.&lt;/P&gt;&lt;P&gt;You could try this as well:&lt;/P&gt;&lt;P&gt;"sh access-list | in object|object-group"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Akshay Rastogi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2015 20:08:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/delete-unused-object-groups/m-p/2768252#M177688</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-10-15T20:08:22Z</dc:date>
    </item>
    <item>
      <title>HiIf an object or object</title>
      <link>https://community.cisco.com/t5/network-security/delete-unused-object-groups/m-p/2768253#M177689</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;If an object or object-group is referenced in an ACL you can't remove that object/object-group. It will say that the object/object-group is referenced and can't be removed. So just try and remove them and you will notice which are used and which are not used.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2015 20:12:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/delete-unused-object-groups/m-p/2768253#M177689</guid>
      <dc:creator>Henrik Grankvist</dc:creator>
      <dc:date>2015-10-15T20:12:19Z</dc:date>
    </item>
    <item>
      <title>Kind of risky, dont you think</title>
      <link>https://community.cisco.com/t5/network-security/delete-unused-object-groups/m-p/2768254#M177690</link>
      <description>&lt;P&gt;Kind of risky, dont you think? &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;&lt;P&gt;If there is not an easy way, I will one one by one &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; hahahahha&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2015 22:06:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/delete-unused-object-groups/m-p/2768254#M177690</guid>
      <dc:creator>Rolando Valenzuela</dc:creator>
      <dc:date>2015-10-15T22:06:55Z</dc:date>
    </item>
    <item>
      <title>Might be easier too to try</title>
      <link>https://community.cisco.com/t5/network-security/delete-unused-object-groups/m-p/2768255#M177691</link>
      <description>&lt;P&gt;Might be easier too to try using the ASDM. The GUI isn't too bad for seeing the hit counts on the object groups. You can also disable ACLs temporarily before removing them from there. That way if any issues arise, you can easily re-enable without deleting them completely from the command line.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2015 23:53:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/delete-unused-object-groups/m-p/2768255#M177691</guid>
      <dc:creator>Charger1129</dc:creator>
      <dc:date>2015-10-15T23:53:28Z</dc:date>
    </item>
    <item>
      <title>Use ASDM. Just right click on</title>
      <link>https://community.cisco.com/t5/network-security/delete-unused-object-groups/m-p/2768256#M177692</link>
      <description>&lt;P&gt;Use ASDM. Just right click on the object groups in turn&amp;nbsp;and select "where used".&lt;/P&gt;&lt;P&gt;It will pop up a window showing you the configuration bits that reference the highlighted object group.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Oct 2015 04:25:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/delete-unused-object-groups/m-p/2768256#M177692</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-10-16T04:25:40Z</dc:date>
    </item>
    <item>
      <title>I have no idea what can be</title>
      <link>https://community.cisco.com/t5/network-security/delete-unused-object-groups/m-p/2768257#M177693</link>
      <description>&lt;P&gt;I have no idea what can be done with the "User Defined Language", but things like these can be handled with a little bit of scripting.&amp;nbsp;You need:&lt;/P&gt;
&lt;OL&gt;&lt;LI&gt;a file with all the objects/object-groups (only the names)&lt;/LI&gt;&lt;LI&gt;a file with the ACLs or the config that you want to check&lt;/LI&gt;&lt;LI&gt;and of course a system that can run scripts like these&lt;/LI&gt;&lt;/OL&gt;

&lt;PRE&gt;
#!/bin/bash

while read line
do
    echo ""
    echo "$line": 
    echo "===================="
    grep -c "$line" $2
done &amp;lt; "$1"&lt;/PRE&gt;

&lt;P&gt;This script can be called&lt;/P&gt;

&lt;PRE&gt;
./script object-file.txt acl-file.txt&lt;/PRE&gt;

&lt;P&gt;and will give you a line-count for the usage of the&amp;nbsp;object/object-group names.&lt;/P&gt;
&lt;P&gt;I used it once to clean up a FWSM-config with about 20k of ACEs. Probably there are more elegant ways to solve that, but it worked quite well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 17 Oct 2015 23:13:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/delete-unused-object-groups/m-p/2768257#M177693</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2015-10-17T23:13:39Z</dc:date>
    </item>
    <item>
      <title>You could also try a trial</title>
      <link>https://community.cisco.com/t5/network-security/delete-unused-object-groups/m-p/2768258#M177694</link>
      <description>&lt;P&gt;You could also try a trial version (free) of &lt;A href="http://www.solarwinds.com/documentation/fsm/fsmdoc.aspx"&gt;SolarWinds Firewall Security&amp;nbsp;Manager&lt;/A&gt; (FSM). It will analyze your configuration for unused objects and object groups (among many other things).&lt;/P&gt;</description>
      <pubDate>Sun, 18 Oct 2015 02:28:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/delete-unused-object-groups/m-p/2768258#M177694</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-10-18T02:28:35Z</dc:date>
    </item>
    <item>
      <title>Interesting, I will try this</title>
      <link>https://community.cisco.com/t5/network-security/delete-unused-object-groups/m-p/2768259#M177695</link>
      <description>&lt;P&gt;Interesting, I will try this and with &lt;A href="http://www.solarwinds.com/documentation/fsm/fsmdoc.aspx" rel="nofollow"&gt;SolarWinds Firewall Security&amp;nbsp;Manager&lt;/A&gt; per Martin's advice.&lt;/P&gt;</description>
      <pubDate>Sun, 18 Oct 2015 22:19:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/delete-unused-object-groups/m-p/2768259#M177695</guid>
      <dc:creator>Rolando Valenzuela</dc:creator>
      <dc:date>2015-10-18T22:19:27Z</dc:date>
    </item>
    <item>
      <title>Easy way to detect unused</title>
      <link>https://community.cisco.com/t5/network-security/delete-unused-object-groups/m-p/2768260#M177696</link>
      <description>&lt;P&gt;&lt;A href="https://supportforums.cisco.com/discussion/11312081/easy-way-detect-unused-network-objectsgroups-asa"&gt;Easy way to detect unused network objects/groups on ASA&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2017 10:08:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/delete-unused-object-groups/m-p/2768260#M177696</guid>
      <dc:creator>Peter Koltl</dc:creator>
      <dc:date>2017-03-21T10:08:50Z</dc:date>
    </item>
  </channel>
</rss>

