<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: hit counts against object group objects in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/hit-counts-against-object-group-objects/m-p/1103517#M895580</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sh run access-list "name" will display the the access-list as it exists in the config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh access-list "name" will display the full access list including the exploded object-groups and includes the line number they correspond to in the ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, if line 13 has an object group in it... when you do sh access-l "name" you will see multiple instance of "line 13" with a "hitcnt=X" at the end of each object group entry.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Like such:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_acl line 13 extended permit tcp object-group XXX_Ent_Monitoring object-group Ent_Monitoring eq 17000 0xd22e53d4&lt;/P&gt;&lt;P&gt;  access-list outside_acl line 13 extended permit tcp host 10.182.31.60 host 172.19.6.91 eq 17000 (hitcnt=0) 0xf48c6831&lt;/P&gt;&lt;P&gt;  access-list outside_acl line 13 extended permit tcp host 10.182.31.60 host 172.19.6.92 eq 17000 (hitcnt=0) 0x569de0fe&lt;/P&gt;&lt;P&gt;  access-list outside_acl line 13 extended permit tcp host 10.183.31.60 host 172.19.6.91 eq 17000 (hitcnt=0) 0xaece0fd5&lt;/P&gt;&lt;P&gt;  access-list outside_acl line 13 extended permit tcp host 10.183.31.60 host 172.19.6.92 eq 17000 (hitcnt=0) 0xa22933b1&lt;/P&gt;&lt;P&gt;  access-list outside_acl line 13 extended permit tcp host 10.184.31.60 host 172.19.6.91 eq 17000 (hitcnt=0) 0x34463c69&lt;/P&gt;&lt;P&gt;  access-list outside_acl line 13 extended permit tcp host 10.184.31.60 host 172.19.6.92 eq 17000 (hitcnt=0) 0x09b103ca&lt;/P&gt;&lt;P&gt;  access-list outside_acl line 13 extended permit tcp host 10.181.31.60 host 172.19.6.91 eq 17000 (hitcnt=0) 0xc1f77cfb&lt;/P&gt;&lt;P&gt;  access-list outside_acl line 13 extended permit tcp host 10.181.31.60 host 172.19.6.92 eq 17000 (hitcnt=0) 0xc97881bb&lt;/P&gt;&lt;P&gt;  access-list outside_acl line 13 extended permit tcp host 10.186.31.14 host 172.19.6.91 eq 17000 (hitcnt=0) 0xf52becd4&lt;/P&gt;&lt;P&gt;  access-list outside_acl line 13 extended permit tcp host 10.186.31.14 host 172.19.6.92 eq 17000 (hitcnt=0) 0x6fa023ee&lt;/P&gt;&lt;P&gt;  access-list outside_acl line 13 extended permit tcp host 10.186.31.17 host 172.19.6.91 eq 17000 (hitcnt=0) 0x23efa629&lt;/P&gt;&lt;P&gt;  access-list outside_acl line 13 extended permit tcp host 10.186.31.17 host 172.19.6.92 eq 17000 (hitcnt=0) 0xf1cae94e&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 02 Oct 2008 17:50:17 GMT</pubDate>
    <dc:creator>Matthew Warrick</dc:creator>
    <dc:date>2008-10-02T17:50:17Z</dc:date>
    <item>
      <title>hit counts against object group objects</title>
      <link>https://community.cisco.com/t5/network-security/hit-counts-against-object-group-objects/m-p/1103516#M895574</link>
      <description>&lt;P&gt;When the command "sho access-list" is performed, it allows the admin to see what hit counts have occured against each line within an Access-list statement.  However it does not show a hit count with reference to object groups in the ACL.&lt;/P&gt;&lt;P&gt;How can one display the hit counts for the items in the object group(s)?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:52:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/hit-counts-against-object-group-objects/m-p/1103516#M895574</guid>
      <dc:creator>Kevin Melton</dc:creator>
      <dc:date>2019-03-11T13:52:15Z</dc:date>
    </item>
    <item>
      <title>Re: hit counts against object group objects</title>
      <link>https://community.cisco.com/t5/network-security/hit-counts-against-object-group-objects/m-p/1103517#M895580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sh run access-list "name" will display the the access-list as it exists in the config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh access-list "name" will display the full access list including the exploded object-groups and includes the line number they correspond to in the ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, if line 13 has an object group in it... when you do sh access-l "name" you will see multiple instance of "line 13" with a "hitcnt=X" at the end of each object group entry.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Like such:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_acl line 13 extended permit tcp object-group XXX_Ent_Monitoring object-group Ent_Monitoring eq 17000 0xd22e53d4&lt;/P&gt;&lt;P&gt;  access-list outside_acl line 13 extended permit tcp host 10.182.31.60 host 172.19.6.91 eq 17000 (hitcnt=0) 0xf48c6831&lt;/P&gt;&lt;P&gt;  access-list outside_acl line 13 extended permit tcp host 10.182.31.60 host 172.19.6.92 eq 17000 (hitcnt=0) 0x569de0fe&lt;/P&gt;&lt;P&gt;  access-list outside_acl line 13 extended permit tcp host 10.183.31.60 host 172.19.6.91 eq 17000 (hitcnt=0) 0xaece0fd5&lt;/P&gt;&lt;P&gt;  access-list outside_acl line 13 extended permit tcp host 10.183.31.60 host 172.19.6.92 eq 17000 (hitcnt=0) 0xa22933b1&lt;/P&gt;&lt;P&gt;  access-list outside_acl line 13 extended permit tcp host 10.184.31.60 host 172.19.6.91 eq 17000 (hitcnt=0) 0x34463c69&lt;/P&gt;&lt;P&gt;  access-list outside_acl line 13 extended permit tcp host 10.184.31.60 host 172.19.6.92 eq 17000 (hitcnt=0) 0x09b103ca&lt;/P&gt;&lt;P&gt;  access-list outside_acl line 13 extended permit tcp host 10.181.31.60 host 172.19.6.91 eq 17000 (hitcnt=0) 0xc1f77cfb&lt;/P&gt;&lt;P&gt;  access-list outside_acl line 13 extended permit tcp host 10.181.31.60 host 172.19.6.92 eq 17000 (hitcnt=0) 0xc97881bb&lt;/P&gt;&lt;P&gt;  access-list outside_acl line 13 extended permit tcp host 10.186.31.14 host 172.19.6.91 eq 17000 (hitcnt=0) 0xf52becd4&lt;/P&gt;&lt;P&gt;  access-list outside_acl line 13 extended permit tcp host 10.186.31.14 host 172.19.6.92 eq 17000 (hitcnt=0) 0x6fa023ee&lt;/P&gt;&lt;P&gt;  access-list outside_acl line 13 extended permit tcp host 10.186.31.17 host 172.19.6.91 eq 17000 (hitcnt=0) 0x23efa629&lt;/P&gt;&lt;P&gt;  access-list outside_acl line 13 extended permit tcp host 10.186.31.17 host 172.19.6.92 eq 17000 (hitcnt=0) 0xf1cae94e&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Oct 2008 17:50:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/hit-counts-against-object-group-objects/m-p/1103517#M895580</guid>
      <dc:creator>Matthew Warrick</dc:creator>
      <dc:date>2008-10-02T17:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: hit counts against object group objects</title>
      <link>https://community.cisco.com/t5/network-security/hit-counts-against-object-group-objects/m-p/3358244#M895586</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;
&lt;P&gt;I´d like to expand the question... I`m using in an ACL on an IOS-Device (15.5.3)&amp;nbsp;an object-group Service in the ACE - but in &lt;SPAN class="gt-baf-word-clickable"&gt;comparison to an ASA&amp;nbsp;when issuing the&amp;nbsp;"Show ip access-list" Output, not each Service Statement is showing up!&amp;nbsp;Is there something I`ve done wrong or I´ve forgotten in my config? OR is this not possible at all?!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="gt-baf-word-clickable"&gt;e.g.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;IOS:&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;object-group service OBJ-SERVICE_TEST-IOS&lt;/P&gt;
&lt;P&gt;tcp-udp eq 102&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;ip access-list extended ACL_TEST-IOS&lt;/P&gt;
&lt;P&gt;permit object-group OBJ-SERVICE_TEST-IOS any any&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;IOS#sh ip access-lists ACL_TEST-IOS&lt;/P&gt;
&lt;P&gt;Extended IP access list ACL_TEST-IOS&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;10 permit object-group OBJ-SERVICE_TEST-IOS any any (10 matches)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;+++ ONLY ONE LINE&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;ASA:&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;object-group service OBJ-SERVICE_TEST-ASA tcp-udp&lt;/P&gt;
&lt;P&gt;port-object eq 102&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;access-list TEST_ACL-ASA extended permit object-group OBJ-SERVICE_TEST-ASA any4 any4&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;ASA# sh access-list&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;access-list TEST_ACL-ASA line 1 extended permit object-group OBJ-SERVICE_TEST-ASA any4 any4 (hitcnt=10)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;access-list TEST_ACL-ASA line 1 extended permit tcp any4 any4 eq 102 (hitcnt=5)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;access-list TEST_ACL-ASA line 1 extended permit udp any4 any4 eq 102 (hitcnt=5)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;+++ AN ENTRY ALSO FOR EACH SERVICE - TCP/UDP +++&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;gr, Dan&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Mar 2018 19:48:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/hit-counts-against-object-group-objects/m-p/3358244#M895586</guid>
      <dc:creator>whistleblower14</dc:creator>
      <dc:date>2018-03-30T19:48:11Z</dc:date>
    </item>
  </channel>
</rss>

