<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACL Hit Counts in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/acl-hit-counts/m-p/2084756#M395901</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The crypto ACl will only show hitcount when it initiates the VPN tunnel. If the tunnel is initiated from the branch office, hitcount will increase on the branch office, not on the Data Center.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the command for your reference:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa83/command/reference/c5.html#wp2271080"&gt;http://www.cisco.com/en/US/docs/security/asa/asa83/command/reference/c5.html#wp2271080&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The DAP-ip-user-xxxx is the Dynamic Access Policy can get created automatically depending on the policy configured on the ASA when the host connects.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 08 Nov 2012 12:42:07 GMT</pubDate>
    <dc:creator>Jennifer Halim</dc:creator>
    <dc:date>2012-11-08T12:42:07Z</dc:date>
    <item>
      <title>ACL Hit Counts</title>
      <link>https://community.cisco.com/t5/network-security/acl-hit-counts/m-p/2084755#M395871</link>
      <description>&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/message/3778979#3778979" target="_blank"&gt;ACL hit counts&lt;/A&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I jsut needed to clarify something, i have a data Center &amp;amp; branch Office connected to each other through IPSec VPN. I also have SSL-VPn configured on the firewall in my data center, the same firewall on which the IPSec VPn from my branch offfice terminates.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I retrieved some ACL logs from the ASA in the data center and all the hit counts shon are zero even when the connection is established and my branch office users are able to access all resources.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;e.g. access-list&lt;STRONG&gt; CRYPTO_XXXXX &lt;/STRONG&gt;line 8 extended permit ip x.x.x.x 255.255.0.0 y.y.y.y 255.255.255.0 (hitcnt=0) 0x8142efc9&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All the ACL are like this where y.y.y.y is the branch office subnet&lt;/P&gt;&lt;P&gt;I also have another ACL which poped up on my SSL VPN ACL as shown below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;e.g. access-list &lt;STRONG&gt;DAP-ip-user-906E4E06 &lt;/STRONG&gt;line 1 extended permit ip x.x.x.x 255.255.255.0 host y.y.y.y (hitcnt=22162) 0x440bdd04&lt;/P&gt;&lt;P&gt;access-list &lt;STRONG&gt;SSLVPN-CORP-ACL &lt;/STRONG&gt;line 1 extended permit ip x.x.x.x 255.255.255.0 host y.y.y.y(hitcnt=0) 0xc9d27468&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can anyone tell me why is my hit count is zero for both CRYPTO ACL and the SSLVPN-CORP-ACL even when the connection is established?&lt;/P&gt;&lt;P&gt;Second, what is &lt;STRONG&gt;DAP-ip-user-906E4E06? &lt;/STRONG&gt;why is it showing such?&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt;"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Thanks a lot in advance.&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt;"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt;"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt;"&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:20:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-hit-counts/m-p/2084755#M395871</guid>
      <dc:creator>Suresh Varghese</dc:creator>
      <dc:date>2019-03-12T00:20:33Z</dc:date>
    </item>
    <item>
      <title>ACL Hit Counts</title>
      <link>https://community.cisco.com/t5/network-security/acl-hit-counts/m-p/2084756#M395901</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The crypto ACl will only show hitcount when it initiates the VPN tunnel. If the tunnel is initiated from the branch office, hitcount will increase on the branch office, not on the Data Center.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the command for your reference:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa83/command/reference/c5.html#wp2271080"&gt;http://www.cisco.com/en/US/docs/security/asa/asa83/command/reference/c5.html#wp2271080&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The DAP-ip-user-xxxx is the Dynamic Access Policy can get created automatically depending on the policy configured on the ASA when the host connects.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Nov 2012 12:42:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-hit-counts/m-p/2084756#M395901</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-11-08T12:42:07Z</dc:date>
    </item>
    <item>
      <title>ACL Hit Counts</title>
      <link>https://community.cisco.com/t5/network-security/acl-hit-counts/m-p/2084757#M395903</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jennifer,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;many thanks for the response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I totally agree regarding the traffic initiation and hit count. I have totally 5 branch office and the same traffic initiation test when i try on the other branch offices, i can see the increase on their respective firewalls.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea what might be wrong with the fiorst branch and why the hitcount does not increase.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The DAP policies were created 2-3 years back and i havent seen any such logs so far, i think this is the first time.&lt;/P&gt;&lt;P&gt;I have used RSA appliance for authenticating the users and remember enabling RADIUS on it. Will it cause of that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Nov 2012 13:03:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-hit-counts/m-p/2084757#M395903</guid>
      <dc:creator>Suresh Varghese</dc:creator>
      <dc:date>2012-11-08T13:03:22Z</dc:date>
    </item>
  </channel>
</rss>

