<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5520 ACL Counters not Incrementing in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5520-acl-counters-not-incrementing/m-p/1697168#M556539</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I depends on purpose of ACL.&lt;/P&gt;&lt;P&gt;If is used for NAT, then no hits will show.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 05 May 2011 06:37:39 GMT</pubDate>
    <dc:creator>Pavel Pokorny</dc:creator>
    <dc:date>2011-05-05T06:37:39Z</dc:date>
    <item>
      <title>ASA 5520 ACL Counters not Incrementing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-acl-counters-not-incrementing/m-p/1697167#M556538</link>
      <description>&lt;P&gt;Hello everyone:&lt;/P&gt;&lt;P&gt;Has anyone seen an ASA not record hit against an ACL? I have two 5520s in a Primary/Secondary configuration, versions 8.4(1) and ASDM 6.4(1). There are several ACLs that are all recording zero hits but I know for a fact that those are what are matching for them to get out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts would be appreciated!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:29:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-acl-counters-not-incrementing/m-p/1697167#M556538</guid>
      <dc:creator>Michael All</dc:creator>
      <dc:date>2019-03-11T20:29:25Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 ACL Counters not Incrementing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-acl-counters-not-incrementing/m-p/1697168#M556539</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I depends on purpose of ACL.&lt;/P&gt;&lt;P&gt;If is used for NAT, then no hits will show.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 May 2011 06:37:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-acl-counters-not-incrementing/m-p/1697168#M556539</guid>
      <dc:creator>Pavel Pokorny</dc:creator>
      <dc:date>2011-05-05T06:37:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 ACL Counters not Incrementing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-acl-counters-not-incrementing/m-p/1697169#M556541</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the response Pavel, but these are not being used to define a NAT. Any other situations that could reflect this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 May 2011 14:51:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-acl-counters-not-incrementing/m-p/1697169#M556541</guid>
      <dc:creator>Michael All</dc:creator>
      <dc:date>2011-05-05T14:51:47Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 ACL Counters not Incrementing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-acl-counters-not-incrementing/m-p/1697170#M556543</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Michael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are those ACL's poiting to the translated or to the realIP address?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 May 2011 18:58:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-acl-counters-not-incrementing/m-p/1697170#M556543</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-05-05T18:58:20Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 ACL Counters not Incrementing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-acl-counters-not-incrementing/m-p/1697171#M556545</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Micheal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you verify if you are able to see the hit count from the CLI, by doing "show access-list". This could be an issue with the ASDM itself, it may not able to calculate the MD5 hash value for the ACL.&lt;/P&gt;&lt;P&gt;Could youm also tell me if those particular ACL's contain any network object for protocol???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 May 2011 19:06:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-acl-counters-not-incrementing/m-p/1697171#M556545</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-05-05T19:06:26Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 ACL Counters not Incrementing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-acl-counters-not-incrementing/m-p/1697172#M556546</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you put the ACL here and tell me purpose?&lt;/P&gt;&lt;P&gt;If there are any groups (networks, services) please decode them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 May 2011 06:16:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-acl-counters-not-incrementing/m-p/1697172#M556546</guid>
      <dc:creator>Pavel Pokorny</dc:creator>
      <dc:date>2011-05-06T06:16:49Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 ACL Counters not Incrementing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-acl-counters-not-incrementing/m-p/1697173#M556547</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Pavel,&lt;/P&gt;&lt;P&gt;One of them is for allowing VPN and SSH connections out:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;TABLE border="1" cellspacing="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;9&lt;/TD&gt;&lt;TD&gt;True&lt;/TD&gt;&lt;TD&gt;172.20.0.0/255.255.0.0&lt;/TD&gt;&lt;TD&gt;any&lt;/TD&gt;&lt;TD&gt;VPNAccess&lt;BR /&gt;tcp/ssh&lt;/TD&gt;&lt;TD&gt;Permit&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;Default&lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;TD&gt;Notes&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The "VPNAccess" Service Group is grouping TCP/10000, UDP/4500, UDP/isakmp, and UDP/10000&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 May 2011 15:46:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-acl-counters-not-incrementing/m-p/1697173#M556547</guid>
      <dc:creator>Michael All</dc:creator>
      <dc:date>2011-05-09T15:46:32Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 ACL Counters not Incrementing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-acl-counters-not-incrementing/m-p/1697174#M556548</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Varun,&lt;/P&gt;&lt;P&gt;Looks like you might have called it... CLI is showing hits while the ASDM is not. Any thoughts on how to resolve this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_access_in line 18 extended permit object-group DM_INLINE_SERVICE_19 object 172.20.0.0 any 0x6c207492 &lt;/P&gt;&lt;P&gt;&amp;nbsp; access-list inside_access_in line 18 extended permit udp 172.20.0.0 255.255.0.0 any eq 4500 (hitcnt=118) 0xd4341637 &lt;/P&gt;&lt;P&gt;&amp;nbsp; access-list inside_access_in line 18 extended permit udp 172.20.0.0 255.255.0.0 any eq isakmp (hitcnt=251) 0xd65313e6 &lt;/P&gt;&lt;P&gt;&amp;nbsp; access-list inside_access_in line 18 extended permit tcp 172.20.0.0 255.255.0.0 any eq ssh (hitcnt=580) 0x6e035ce4 &lt;/P&gt;&lt;P&gt;&amp;nbsp; access-list inside_access_in line 18 extended permit tcp 172.20.0.0 255.255.0.0 any eq 10000 (hitcnt=13) 0x2a249aa3 &lt;/P&gt;&lt;P&gt;&amp;nbsp; access-list inside_access_in line 18 extended permit udp 172.20.0.0 255.255.0.0 any eq 10000 (hitcnt=8) 0xf7e045eb &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 May 2011 15:52:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-acl-counters-not-incrementing/m-p/1697174#M556548</guid>
      <dc:creator>Michael All</dc:creator>
      <dc:date>2011-05-09T15:52:48Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 ACL Counters not Incrementing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-acl-counters-not-incrementing/m-p/1697175#M556549</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Micheal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the ASDM under firewall dashboard, do you see a message for config out of sync? If yes,this might be a known issue withe ASA, my suggestions to you would be to open a TAC case for further investigation on it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 May 2011 17:10:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-acl-counters-not-incrementing/m-p/1697175#M556549</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-05-09T17:10:26Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 ACL Counters not Incrementing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-acl-counters-not-incrementing/m-p/1697176#M556550</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Varun,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You're probably right.&lt;/P&gt;&lt;P&gt;I've seen this behaviour under different types os ASA code (8.2.4 ie) and also ASDM (6.3.x).&lt;/P&gt;&lt;P&gt;So, maybe TAC will help and devel update code of ASDM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bye&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 May 2011 17:34:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-acl-counters-not-incrementing/m-p/1697176#M556550</guid>
      <dc:creator>Pavel Pokorny</dc:creator>
      <dc:date>2011-05-09T17:34:50Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 ACL Counters not Incrementing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-acl-counters-not-incrementing/m-p/1697177#M556551</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay, makes sense, I'll open a ticket with Cisco. Thanks for the help guys.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 May 2011 18:14:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-acl-counters-not-incrementing/m-p/1697177#M556551</guid>
      <dc:creator>Michael All</dc:creator>
      <dc:date>2011-05-09T18:14:54Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 ACL Counters not Incrementing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-acl-counters-not-incrementing/m-p/1697178#M556552</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the bug&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCtl99214"&gt;http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCtl99214&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 May 2011 20:47:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-acl-counters-not-incrementing/m-p/1697178#M556552</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-05-17T20:47:02Z</dc:date>
    </item>
  </channel>
</rss>

