<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: access-list hit count in FTD in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/access-list-hit-count-in-ftd/m-p/3867142#M925478</link>
    <description>&lt;P&gt;Have you selected "Log at beginning of Connection" in the ACP rule and also indicated that the log destination should be the Event Viewer?&lt;/P&gt;</description>
    <pubDate>Tue, 04 Jun 2019 03:13:59 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2019-06-04T03:13:59Z</dc:date>
    <item>
      <title>access-list hit count in FTD</title>
      <link>https://community.cisco.com/t5/network-security/access-list-hit-count-in-ftd/m-p/3865401#M925474</link>
      <description>&lt;P&gt;We have FMC ( Ver 6.2.3.3 ) anf FTD ASA5516-x now .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have set access control policy with application + URL , but I can't see any hit count on FTD.&lt;/P&gt;&lt;P&gt;&amp;gt; show running-config | grep 268439554&lt;BR /&gt;access-list CSM_FW_ACL_ remark rule-id 268439554: ACCESS POLICY: BFTD_Base - Mandatory&lt;BR /&gt;access-list CSM_FW_ACL_ remark rule-id 268439554: L7 RULE: PCI-to-Block&lt;BR /&gt;access-list CSM_FW_ACL_ advanced permit ip ifc PCI object BAJA_PCI ifc Internet_Alestra any4 rule-id 268439554&lt;BR /&gt;access-list CSM_FW_ACL_ advanced permit ip ifc NONPCI object BAJA_PCI ifc Internet_Alestra any4 rule-id 268439554&lt;BR /&gt;&amp;gt; show access-list | grep 268439554&lt;BR /&gt;access-list CSM_FW_ACL_ line 159 remark rule-id 268439554: ACCESS POLICY: BFTD_Base - Mandatory&lt;BR /&gt;access-list CSM_FW_ACL_ line 160 remark rule-id 268439554: L7 RULE: PCI-to-Block&lt;BR /&gt;access-list CSM_FW_ACL_ line 161 advanced permit ip ifc PCI object BAJA_PCI ifc Internet_Alestra any4 rule-id 268439554 (hitcnt=0) 0x68dbf84e&lt;BR /&gt;access-list CSM_FW_ACL_ line 161 advanced permit ip ifc PCI 10.48.20.0 255.255.255.0 ifc Internet_Alestra any4 rule-id 268439554 (hitcnt=0) 0x68dbf84e&lt;BR /&gt;access-list CSM_FW_ACL_ line 162 advanced permit ip ifc NONPCI object BAJA_PCI ifc Internet_Alestra any4 rule-id 268439554 (hitcnt=0) 0xa07662a7&lt;BR /&gt;access-list CSM_FW_ACL_ line 162 advanced permit ip ifc NONPCI 10.48.20.0 255.255.255.0 ifc Internet_Alestra any4 rule-id 268439554 (hitcnt=0) 0xa07662a7&lt;BR /&gt;&amp;gt;&lt;/P&gt;&lt;P&gt;How can I verify what wrong i have ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2019-05-30_11-28-14.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/37721iF1FF2A2DA3F88AC3/image-size/large?v=v2&amp;amp;px=999" role="button" title="2019-05-30_11-28-14.jpg" alt="2019-05-30_11-28-14.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:10:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-hit-count-in-ftd/m-p/3865401#M925474</guid>
      <dc:creator>jkim3</dc:creator>
      <dc:date>2020-02-21T17:10:56Z</dc:date>
    </item>
    <item>
      <title>Re: access-list hit count in FTD</title>
      <link>https://community.cisco.com/t5/network-security/access-list-hit-count-in-ftd/m-p/3865517#M925475</link>
      <description>&lt;P&gt;Are you showing any Block connection events (in FMC Event viewer) that are a result of the configured rule?&lt;/P&gt;
&lt;P&gt;The hit count definitely works in FTD cli - I just confirmed on a system running 6.2.3.11.&lt;/P&gt;
&lt;P&gt;Try using this command:&lt;/P&gt;
&lt;PRE&gt;&amp;gt; show access-list | exclude hitcnt=0&lt;/PRE&gt;</description>
      <pubDate>Fri, 31 May 2019 02:18:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-hit-count-in-ftd/m-p/3865517#M925475</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-05-31T02:18:03Z</dc:date>
    </item>
    <item>
      <title>Re: access-list hit count in FTD</title>
      <link>https://community.cisco.com/t5/network-security/access-list-hit-count-in-ftd/m-p/3866911#M925476</link>
      <description>&lt;P&gt;Hi Marvin ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply , but I am so confused why I can't see log&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; show access-list | grep 268440579&lt;BR /&gt;access-list CSM_FW_ACL_ line 138 remark rule-id 268440579: ACCESS POLICY: BFTD_Base - Mandatory&lt;BR /&gt;access-list CSM_FW_ACL_ line 139 remark rule-id 268440579: L7 RULE: PCI-to-Block&lt;BR /&gt;access-list CSM_FW_ACL_ line 140 advanced permit ip ifc PCI object BAJA_PCI ifc Internet_Alestra any4 rule-id 268440579 (hitcnt=824) 0x68dbf84e&lt;BR /&gt;access-list CSM_FW_ACL_ line 140 advanced permit ip ifc PCI 10.48.20.0 255.255.255.0 ifc Internet_Alestra any4 rule-id 268440579 (hitcnt=824) 0x68dbf84e&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After I clear the counter , I see 824 hits , but I can't see any log&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2019 16:39:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-hit-count-in-ftd/m-p/3866911#M925476</guid>
      <dc:creator>jkim3</dc:creator>
      <dc:date>2019-06-03T16:39:36Z</dc:date>
    </item>
    <item>
      <title>Re: access-list hit count in FTD</title>
      <link>https://community.cisco.com/t5/network-security/access-list-hit-count-in-ftd/m-p/3866933#M925477</link>
      <description>&lt;P&gt;Hi Marvin ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As we saw hit count is increased then before , But I can't see any block log on FMC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; show access-list | grep 268440579&lt;BR /&gt;access-list CSM_FW_ACL_ line 138 remark rule-id 268440579: ACCESS POLICY: BFTD_Base - Mandatory&lt;BR /&gt;access-list CSM_FW_ACL_ line 139 remark rule-id 268440579: L7 RULE: PCI-to-Block&lt;BR /&gt;access-list CSM_FW_ACL_ line 140 advanced permit ip ifc PCI object BAJA_PCI ifc Internet_Alestra any4 rule-id 268440579 (hitcnt=48315) 0x68dbf84e&lt;BR /&gt;access-list CSM_FW_ACL_ line 140 advanced permit ip ifc PCI 10.48.20.0 255.255.255.0 ifc Internet_Alestra any4 rule-id 268440579 (hitcnt=48315) 0x68dbf84e&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2019 17:15:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-hit-count-in-ftd/m-p/3866933#M925477</guid>
      <dc:creator>jkim3</dc:creator>
      <dc:date>2019-06-03T17:15:59Z</dc:date>
    </item>
    <item>
      <title>Re: access-list hit count in FTD</title>
      <link>https://community.cisco.com/t5/network-security/access-list-hit-count-in-ftd/m-p/3867142#M925478</link>
      <description>&lt;P&gt;Have you selected "Log at beginning of Connection" in the ACP rule and also indicated that the log destination should be the Event Viewer?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2019 03:13:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-hit-count-in-ftd/m-p/3867142#M925478</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-06-04T03:13:59Z</dc:date>
    </item>
    <item>
      <title>Re: access-list hit count in FTD</title>
      <link>https://community.cisco.com/t5/network-security/access-list-hit-count-in-ftd/m-p/3867471#M925506</link>
      <description>&lt;P&gt;Hi Marvin ,&lt;/P&gt;&lt;P&gt;You're right . It is checked log at beginning of connection .&lt;/P&gt;&lt;P&gt;I can't check log at end of connection . The box is deactivated . why ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't see any events as below . it is extended 6 hours&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="2019-06-04_7-50-40.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/37997iE3BD3DDF98574EC2/image-size/large?v=v2&amp;amp;px=999" role="button" title="2019-06-04_7-50-40.png" alt="2019-06-04_7-50-40.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2019 14:55:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-hit-count-in-ftd/m-p/3867471#M925506</guid>
      <dc:creator>jkim3</dc:creator>
      <dc:date>2019-06-04T14:55:00Z</dc:date>
    </item>
    <item>
      <title>Re: access-list hit count in FTD</title>
      <link>https://community.cisco.com/t5/network-security/access-list-hit-count-in-ftd/m-p/3869267#M925507</link>
      <description>&lt;P&gt;Because action is block , I can't choose log of end of connection . System block traffic start of connection .&lt;/P&gt;&lt;P&gt;And I can see log now .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2019 03:22:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-hit-count-in-ftd/m-p/3869267#M925507</guid>
      <dc:creator>jkim3</dc:creator>
      <dc:date>2019-06-07T03:22:57Z</dc:date>
    </item>
  </channel>
</rss>

