<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unused rules tracking in PIX in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/unused-rules-tracking-in-pix/m-p/1801851#M493176</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have PIX 535 and using ACLs for allowing traffic. I need to clean up the rule base. I would like to know how to fetch a report of Unused rules for long time?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also when a traffic is being allowed, I want to know through which rule number its being allowed?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know how to get the above things done.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lenin. S&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 21:51:01 GMT</pubDate>
    <dc:creator>leninstcs</dc:creator>
    <dc:date>2019-03-11T21:51:01Z</dc:date>
    <item>
      <title>Unused rules tracking in PIX</title>
      <link>https://community.cisco.com/t5/network-security/unused-rules-tracking-in-pix/m-p/1801851#M493176</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have PIX 535 and using ACLs for allowing traffic. I need to clean up the rule base. I would like to know how to fetch a report of Unused rules for long time?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also when a traffic is being allowed, I want to know through which rule number its being allowed?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know how to get the above things done.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lenin. S&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:51:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unused-rules-tracking-in-pix/m-p/1801851#M493176</guid>
      <dc:creator>leninstcs</dc:creator>
      <dc:date>2019-03-11T21:51:01Z</dc:date>
    </item>
    <item>
      <title>Re: Unused rules tracking in PIX</title>
      <link>https://community.cisco.com/t5/network-security/unused-rules-tracking-in-pix/m-p/1801852#M493178</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can simply do this the old way which is&amp;nbsp;&amp;nbsp; looking at&amp;nbsp; your access list hit count.&amp;nbsp;&amp;nbsp; Depending how big is your organization on how many firewalls you have to do this clean up&amp;nbsp; will depend on the method&amp;nbsp; you use.&amp;nbsp; If&amp;nbsp; you are talking about one firewall do it the manual inexpensive way, which is&amp;nbsp;&amp;nbsp; " show access-list&amp;nbsp; "&amp;nbsp; and take&amp;nbsp; a base line perpahs every other day or once per week of ACLs hit counts.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; If may firewalls&amp;nbsp; then you can look for 3rd party software out there to do it for you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In addition:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can reset the ACL counters like this, to sort of create a baseline of your acl counters:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;#clear access-list &lt;ACL_NAME&gt;&amp;nbsp; counters&lt;/ACL_NAME&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then you can&amp;nbsp; use&amp;nbsp;&amp;nbsp; " show access-list "&amp;nbsp;&amp;nbsp; to see hit counts&amp;nbsp;&amp;nbsp; ,&amp;nbsp;&amp;nbsp; for the ones that there is no hit counts say for a week or two&amp;nbsp; those are targeted to investigate&amp;nbsp; before you remove. And when removing&amp;nbsp; always&amp;nbsp; save a copy for backup in case you need to revert. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Nov 2011 19:56:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unused-rules-tracking-in-pix/m-p/1801852#M493178</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2011-11-15T19:56:04Z</dc:date>
    </item>
    <item>
      <title>Re: Unused rules tracking in PIX</title>
      <link>https://community.cisco.com/t5/network-security/unused-rules-tracking-in-pix/m-p/1801853#M493180</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks a lot. Jorge. I worked out for me your idea. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to know one more thing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only denied logs are getting logged in my syslog server now. I would like to save the allowed logs also, for the forensics later. How should I enable that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is enabiling log in evey line of access-list must for this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Nov 2011 06:10:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unused-rules-tracking-in-pix/m-p/1801853#M493180</guid>
      <dc:creator>leninstcs</dc:creator>
      <dc:date>2011-11-27T06:10:38Z</dc:date>
    </item>
  </channel>
</rss>

