<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 0 hits on access rule in use in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/0-hits-on-access-rule-in-use/m-p/2320240#M345628</link>
    <description>&lt;P&gt; Last week I disabled several rules on our ASA because the rules had 0 hits. Well one of the rules needed to be re-enabled to allow a department access to an application. It works after re-enabling the rule, but I don't understand why am I not seeing any hits on the rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to cleanup our access rules and I figured I could do away with the ones getting 0 hits. But if that isn't an indicator to the rule being in use or not, then what is. &lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 02:18:33 GMT</pubDate>
    <dc:creator>Eric Washington</dc:creator>
    <dc:date>2019-03-12T02:18:33Z</dc:date>
    <item>
      <title>0 hits on access rule in use</title>
      <link>https://community.cisco.com/t5/network-security/0-hits-on-access-rule-in-use/m-p/2320240#M345628</link>
      <description>&lt;P&gt; Last week I disabled several rules on our ASA because the rules had 0 hits. Well one of the rules needed to be re-enabled to allow a department access to an application. It works after re-enabling the rule, but I don't understand why am I not seeing any hits on the rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to cleanup our access rules and I figured I could do away with the ones getting 0 hits. But if that isn't an indicator to the rule being in use or not, then what is. &lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:18:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/0-hits-on-access-rule-in-use/m-p/2320240#M345628</guid>
      <dc:creator>Eric Washington</dc:creator>
      <dc:date>2019-03-12T02:18:33Z</dc:date>
    </item>
    <item>
      <title>0 hits on access rule in use</title>
      <link>https://community.cisco.com/t5/network-security/0-hits-on-access-rule-in-use/m-p/2320241#M345629</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont personally remember any occasion where a hitcount on an ACL would have not been a clear indicator if that rule was usefull or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure if you are using ASDM, if you are then there is naturally always the chance that it has something to do with ASDM. Perhaps a bug. For example I have witnessed VPN counters on the ASDM that were incorrect and completely different compare to what the ASA was telling me on the CLI. Maybe updating the ASDM might be one step.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have confirmed these statistics from the CLI then it would seem a lot stranger.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would imagine that you are talking about interface ACLs here only?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I only mention this because for example NAT0 related ACL never get their hitcount increased even though they are in use all the time. So one idea would be to check if the disabled rule was actually in an ACL that was used for NAT0? As I said, NAT0 ACL dont get any hitcounts even though they are in use.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would also suggest you to use the &lt;STRONG&gt;"packet-tracer"&lt;/STRONG&gt; command on the CLI to simulate the traffic that should match this ACL rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The&lt;STRONG&gt; "packet-tracer"&lt;/STRONG&gt; output should both reference this ACL rule if it matches to it (and nothing before that rule) and it should also increase the hitcount for that rule even though no real traffic might have come through the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Jul 2013 17:06:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/0-hits-on-access-rule-in-use/m-p/2320241#M345629</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-07-29T17:06:17Z</dc:date>
    </item>
    <item>
      <title>0 hits on access rule in use</title>
      <link>https://community.cisco.com/t5/network-security/0-hits-on-access-rule-in-use/m-p/2320242#M345630</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jouni!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes it is ASDM that I'm using. So how would I check the amount of hits the access rule receives from the CLI?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Jul 2013 17:12:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/0-hits-on-access-rule-in-use/m-p/2320242#M345630</guid>
      <dc:creator>Eric Washington</dc:creator>
      <dc:date>2013-07-29T17:12:26Z</dc:date>
    </item>
    <item>
      <title>0 hits on access rule in use</title>
      <link>https://community.cisco.com/t5/network-security/0-hits-on-access-rule-in-use/m-p/2320243#M345631</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I went into ASDM, right clicked on the rule, and started the packet trace.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I get green check marks for capture, access-list, and route-lookup. The result is the packet is dropped with info saying: &lt;/P&gt;&lt;P&gt;(sp-security-failed) Slowpath security checks failed &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Jul 2013 17:16:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/0-hits-on-access-rule-in-use/m-p/2320243#M345631</guid>
      <dc:creator>Eric Washington</dc:creator>
      <dc:date>2013-07-29T17:16:19Z</dc:date>
    </item>
    <item>
      <title>0 hits on access rule in use</title>
      <link>https://community.cisco.com/t5/network-security/0-hits-on-access-rule-in-use/m-p/2320244#M345632</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well you can go to the CLI and use&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This command to show all the ACLs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show access-list&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This command to show certain ACL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show access-list &lt;ACL name=""&gt;&lt;/ACL&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have a certain line number for the rule you can use this command for example&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show access-list &lt;ACL name=""&gt; | inc line #&lt;/ACL&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where # = number&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also do these through the ASDM by going to&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Tools&lt;/LI&gt;&lt;LI&gt;Command Line Interface&lt;/LI&gt;&lt;LI&gt;Enter the command to the field and send it to the device and it will print the CLI output for you&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Jul 2013 17:18:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/0-hits-on-access-rule-in-use/m-p/2320244#M345632</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-07-29T17:18:55Z</dc:date>
    </item>
    <item>
      <title>0 hits on access rule in use</title>
      <link>https://community.cisco.com/t5/network-security/0-hits-on-access-rule-in-use/m-p/2320245#M345633</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just figured it out as you posted this haha. Thanks Jouni!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible that the rule doesn't show any hits because of the destination ip's doesn't have any? Here is my output from CLI:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WHQ-ASA-01/pri/act# sh access-list | i 153.69.200.107&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-list inside_access_in line 205 extended permit tcp any range 1 65535 host 153.69.200.107 eq https (hitcnt=735) 0x1053b8b2&lt;/P&gt;&lt;P&gt;WHQ-ASA-01/pri/act# sh access-list | i 153.69.200.110&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-list inside_access_in line 205 extended permit tcp any range 1 65535 host 153.69.200.110 eq https (hitcnt=0) 0x3027e0d8&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Those are the two destinations in the rule and only one has hits. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Jul 2013 17:23:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/0-hits-on-access-rule-in-use/m-p/2320245#M345633</guid>
      <dc:creator>Eric Washington</dc:creator>
      <dc:date>2013-07-29T17:23:20Z</dc:date>
    </item>
    <item>
      <title>Re: 0 hits on access rule in use</title>
      <link>https://community.cisco.com/t5/network-security/0-hits-on-access-rule-in-use/m-p/2320246#M345634</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Notice that both rules are with the same line number of 205&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This can only mean that they are part of an ACL rule/line that uses an &lt;STRONG&gt;"object-group"&lt;/STRONG&gt; in them. Seems that the destination IP addresses are defined under the &lt;STRONG&gt;"object-group network &lt;NAME&gt;"&lt;/NAME&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This probably means that you have disabled the ACL rule/line at 205 which contains this actual &lt;STRONG&gt;"object-group network &lt;NAME&gt;"&lt;/NAME&gt;&lt;/STRONG&gt; and therefore you have removed a lot more rules than just the one with 0 hitcount.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Use the command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show access-list inside_access_in | inc line 205&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and check what the &lt;STRONG&gt;"object-group"&lt;/STRONG&gt; is that is used in the ACL rule at line 205.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to remove the hosts with 0 hitcount THEN you will have to remove them from inside the &lt;STRONG&gt;"object-group"&lt;/STRONG&gt; and NOT disable the whole ACL rule/line (which effect a lot more hosts)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Though you will have to make sure that this &lt;STRONG&gt;"object-group"&lt;/STRONG&gt; is not used in any other configuration where removing one host under it might cause problems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So it starting to seem like the reason disabling a rule affected some application is because you disabled a single ACL rule that used an &lt;STRONG&gt;"object-group" &lt;/STRONG&gt;to define multiple destination IP addresses while you should have removed the IP addresses from under the &lt;STRONG&gt;"object-group"&lt;/STRONG&gt; (the ones that are not getting hitcount) rather than disable the whole rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Jul 2013 17:27:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/0-hits-on-access-rule-in-use/m-p/2320246#M345634</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-07-29T17:27:26Z</dc:date>
    </item>
    <item>
      <title>0 hits on access rule in use</title>
      <link>https://community.cisco.com/t5/network-security/0-hits-on-access-rule-in-use/m-p/2320247#M345635</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is the rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WHQ-ASA-01/pri/act# sh access-list | i inside_access_in line 205&lt;/P&gt;&lt;P&gt;access-list inside_access_in line 205 extended permit object https any object-group DM_INLINE_NETWORK_60 0xcfce8697&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-list inside_access_in line 205 extended permit tcp any range 1 65535 host 153.69.200.107 eq https (hitcnt=735) 0x1053b8b2&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-list inside_access_in line 205 extended permit tcp any range 1 65535 host 153.69.200.110 eq https (hitcnt=0) 0x3027e0d8&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I only disabled the rule because it showed a 0 hit count in ASDM and still continues to. But from the CLI we can actually see one of the ip's getting hits. So am I correct to think that the rule shows 0 hits in ASDM because there's a host in the rule's destination field not getting any hits?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Jul 2013 17:36:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/0-hits-on-access-rule-in-use/m-p/2320247#M345635</guid>
      <dc:creator>Eric Washington</dc:creator>
      <dc:date>2013-07-29T17:36:09Z</dc:date>
    </item>
    <item>
      <title>Re: 0 hits on access rule in use</title>
      <link>https://community.cisco.com/t5/network-security/0-hits-on-access-rule-in-use/m-p/2320248#M345636</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I edited the the above reply a couple of times when you were probably already replying.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use the command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show run object-group id DM_INLINE_NETWORK_60 &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To view only the configuration related to that &lt;STRONG&gt;"object-group"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to the above it does contain only 2 host IP addresses so the configuration is probably something like this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object-group network DM_INLINE_NETWORK_60&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; network-object host 153.69.200.107&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; network-object host 153.69.200.110&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So in this case if this &lt;STRONG&gt;"object-group"&lt;/STRONG&gt; is not used anywhere else, you should be able to to remove the IP that is not getting any hitcount with the following commands&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First go under the &lt;STRONG&gt;"object-group"&lt;/STRONG&gt; configuration mode then remove the single host address from there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object-group network DM_INLINE_NETWORK_60&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; no network-object host 153.69.200.110&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After this you should only see that one rule on the line 205 of the ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Jul 2013 17:42:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/0-hits-on-access-rule-in-use/m-p/2320248#M345636</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-07-29T17:42:28Z</dc:date>
    </item>
    <item>
      <title>0 hits on access rule in use</title>
      <link>https://community.cisco.com/t5/network-security/0-hits-on-access-rule-in-use/m-p/2320249#M345637</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks again Jouni!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know how to remove the host from the rule - that isn't the issue. I want to know if that host that isn't receiving hits the reason that the entire rule doesn't show hits in ASDM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So basically if I remove that one address that ends in .110, will ASDM begin to show hits on the rule since the .107 address is getting hits?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Jul 2013 17:54:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/0-hits-on-access-rule-in-use/m-p/2320249#M345637</guid>
      <dc:creator>Eric Washington</dc:creator>
      <dc:date>2013-07-29T17:54:12Z</dc:date>
    </item>
    <item>
      <title>Re: 0 hits on access rule in use</title>
      <link>https://community.cisco.com/t5/network-security/0-hits-on-access-rule-in-use/m-p/2320250#M345638</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did a quick test on my own ASA through ASDM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I allowed ICMP from my LAN to 2 different hosts that configured under an &lt;STRONG&gt;"object-group"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I only sent ICMP to one of the hosts in that &lt;STRONG&gt;"object-group"&lt;/STRONG&gt; and the ASDM shows hitcounts for that&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/6/4/2/148246-CSC-hit.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the CLI it shows the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list LAN-IN line 1 extended permit icmp any4 object-group DM_INLINE_NETWORK_1 (hitcnt=2) 0xc22fc6f8&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; access-list LAN-IN line 1 extended permit icmp any4 host 1.1.1.1 (hitcnt=2) 0x31b7950c&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; access-list LAN-IN line 1 extended permit icmp any4 host 2.2.2.2 (hitcnt=0) 0xc51d1507&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont know if its related to something in your ASDM or software. I personally am running quite new ASDM and ASA software levels at the moment&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Jul 2013 18:01:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/0-hits-on-access-rule-in-use/m-p/2320250#M345638</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-07-29T18:01:21Z</dc:date>
    </item>
  </channel>
</rss>

