<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Easy way to detect unused network objects/groups on ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/easy-way-to-detect-unused-network-objects-groups-on-asa/m-p/1764895#M496008</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where is this button, I'm now on 7.1.(4) and will find this so useful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 20 Nov 2013 09:10:34 GMT</pubDate>
    <dc:creator>Andy White</dc:creator>
    <dc:date>2013-11-20T09:10:34Z</dc:date>
    <item>
      <title>Easy way to detect unused network objects/groups on ASA</title>
      <link>https://community.cisco.com/t5/network-security/easy-way-to-detect-unused-network-objects-groups-on-asa/m-p/1764890#M496003</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I find that every 6-12 months I will log on to the ASDM and go to the Network Objects/Groups section and spend ages right clicking on each object and seeing if it is still being used and if it isn't I then delete it.&amp;nbsp; It can take a long time as our config is large, are there any better ways of keeping the ASA update to date?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:36:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/easy-way-to-detect-unused-network-objects-groups-on-asa/m-p/1764890#M496003</guid>
      <dc:creator>Andy White</dc:creator>
      <dc:date>2019-03-11T21:36:25Z</dc:date>
    </item>
    <item>
      <title>Easy way to detect unused network objects/groups on ASA</title>
      <link>https://community.cisco.com/t5/network-security/easy-way-to-detect-unused-network-objects-groups-on-asa/m-p/1764891#M496004</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI Andy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You've got a difficult one here, there's no automated way for it, and it might include tedious overhead. You migt first need to run through the config. The best that I can think of is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;lets say you want to check whether object-group DM_INLINE_24 is being used somewhere or not then do:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show run | inc DM_INLINE_24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it returns any ACL or nat statements, then it is being used, otherwise not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Oct 2011 13:41:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/easy-way-to-detect-unused-network-objects-groups-on-asa/m-p/1764891#M496004</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-10-11T13:41:48Z</dc:date>
    </item>
    <item>
      <title>Easy way to detect unused network objects/groups on ASA</title>
      <link>https://community.cisco.com/t5/network-security/easy-way-to-detect-unused-network-objects-groups-on-asa/m-p/1764892#M496005</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Oct 2011 13:43:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/easy-way-to-detect-unused-network-objects-groups-on-asa/m-p/1764892#M496005</guid>
      <dc:creator>Andy White</dc:creator>
      <dc:date>2011-10-11T13:43:53Z</dc:date>
    </item>
    <item>
      <title>Easy way to detect unused network objects/groups on ASA</title>
      <link>https://community.cisco.com/t5/network-security/easy-way-to-detect-unused-network-objects-groups-on-asa/m-p/1764893#M496006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I know that this is a very old post, however, starting in ASDM 7.1(3), there is a "Not Used" button in the app.&amp;nbsp; Click it and it will provide you list of objects/groups that are not being used in ACLs.&amp;nbsp; You can then choose which objects to delete (they're all checked by default).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As of 7.1(4), however, there is no such feature for protocols/protocol groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hopefully this helps someone - I know that it saved me a lot of time in a few firewall migration projects!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rob.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Nov 2013 22:13:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/easy-way-to-detect-unused-network-objects-groups-on-asa/m-p/1764893#M496006</guid>
      <dc:creator>robdog01</dc:creator>
      <dc:date>2013-11-19T22:13:50Z</dc:date>
    </item>
    <item>
      <title>Easy way to detect unused network objects/groups on ASA</title>
      <link>https://community.cisco.com/t5/network-security/easy-way-to-detect-unused-network-objects-groups-on-asa/m-p/1764894#M496007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Very cool!!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Nov 2013 22:52:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/easy-way-to-detect-unused-network-objects-groups-on-asa/m-p/1764894#M496007</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-11-19T22:52:02Z</dc:date>
    </item>
    <item>
      <title>Easy way to detect unused network objects/groups on ASA</title>
      <link>https://community.cisco.com/t5/network-security/easy-way-to-detect-unused-network-objects-groups-on-asa/m-p/1764895#M496008</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where is this button, I'm now on 7.1.(4) and will find this so useful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Nov 2013 09:10:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/easy-way-to-detect-unused-network-objects-groups-on-asa/m-p/1764895#M496008</guid>
      <dc:creator>Andy White</dc:creator>
      <dc:date>2013-11-20T09:10:34Z</dc:date>
    </item>
    <item>
      <title>Easy way to detect unused network objects/groups on ASA</title>
      <link>https://community.cisco.com/t5/network-security/easy-way-to-detect-unused-network-objects-groups-on-asa/m-p/1764896#M496009</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please advise that where to locate this button.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Nov 2013 21:58:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/easy-way-to-detect-unused-network-objects-groups-on-asa/m-p/1764896#M496009</guid>
      <dc:creator>raza555</dc:creator>
      <dc:date>2013-11-25T21:58:16Z</dc:date>
    </item>
    <item>
      <title>Easy way to detect unused network objects/groups on ASA</title>
      <link>https://community.cisco.com/t5/network-security/easy-way-to-detect-unused-network-objects-groups-on-asa/m-p/1764897#M496010</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This one was new to me as well. I searched and could not find mention of it in either the release notes or configuration guide.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To find it, go into the "Configuration, Firewall" section and make sure you have turned on "View, Addresses". You should then see the "Not Used" button as shown below (click to enlarge screenshot):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/8/5/5/167558-Capture.JPG" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Nov 2013 23:10:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/easy-way-to-detect-unused-network-objects-groups-on-asa/m-p/1764897#M496010</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2013-11-25T23:10:26Z</dc:date>
    </item>
    <item>
      <title>Easy way to detect unused network objects/groups on ASA</title>
      <link>https://community.cisco.com/t5/network-security/easy-way-to-detect-unused-network-objects-groups-on-asa/m-p/1764898#M496011</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One more resource-&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="http://www.tunnelsup.com/config-cleanup/"&gt;http://www.tunnelsup.com/config-cleanup/&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Nov 2013 03:57:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/easy-way-to-detect-unused-network-objects-groups-on-asa/m-p/1764898#M496011</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2013-11-26T03:57:16Z</dc:date>
    </item>
    <item>
      <title>Easy way to detect unused network objects/groups on ASA</title>
      <link>https://community.cisco.com/t5/network-security/easy-way-to-detect-unused-network-objects-groups-on-asa/m-p/1764899#M496012</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We noticed a issue with using that button:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;IMG ___jive_emoticon_name="alert" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif" /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN __jive_emoticon_name="alert" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt; If the object has a NAT associated with it, using that button will still show the object is not used and will delete the NAT. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Although when doing a right click on the object and "Where used" will show that it's used in a NAT rule. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Feb 2014 20:19:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/easy-way-to-detect-unused-network-objects-groups-on-asa/m-p/1764899#M496012</guid>
      <dc:creator>Constantin_Pop83</dc:creator>
      <dc:date>2014-02-28T20:19:07Z</dc:date>
    </item>
    <item>
      <title>The best way to delete all of</title>
      <link>https://community.cisco.com/t5/network-security/easy-way-to-detect-unused-network-objects-groups-on-asa/m-p/1764900#M496013</link>
      <description>&lt;P&gt;The best way&amp;nbsp;to delete all of not used objects to&amp;nbsp;delete all objects. If the object is used, the ASA displays an error and not delete it.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2017 08:30:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/easy-way-to-detect-unused-network-objects-groups-on-asa/m-p/1764900#M496013</guid>
      <dc:creator>dit.cor</dc:creator>
      <dc:date>2017-02-08T08:30:52Z</dc:date>
    </item>
    <item>
      <title>Re: Easy way to detect unused network objects/groups on ASA</title>
      <link>https://community.cisco.com/t5/network-security/easy-way-to-detect-unused-network-objects-groups-on-asa/m-p/3821879#M496014</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this problem still exist?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2019 10:02:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/easy-way-to-detect-unused-network-objects-groups-on-asa/m-p/3821879#M496014</guid>
      <dc:creator>dmnsrk</dc:creator>
      <dc:date>2019-03-19T10:02:57Z</dc:date>
    </item>
  </channel>
</rss>

