cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1516
Views
10
Helpful
6
Replies

Disable rule with 0 hits is safe?

marcio.tormente
Level 4
Level 4

Hello guys!

 

I have a firewall with more tham 1500 rules and a lot of then have 0 hits.

I would like to clean the configuration, but I'm noob with firewall and i don´t know if is safe to delete all rules thar there is no hits?

 

Thanks

Marcio

6 Replies 6

akumarka
Cisco Employee
Cisco Employee
no its not safe . hits shows traffic flow .. 0 hits does not means they don't need that access .
it just means no traffic as of now.

Hello Akumarka,

 

How can I make sure that one rule is not in use to be deleted?

 

Thanks

u can clean multiple entry .for example
if u have supersubnet for specific smaller subnet than u can cleanup smaller subnets .only if rule are same

if u changed subnets for site or access changed , you want to restrict some specific subnets then you can clean up unwanted the rules .

mainly rules are already there for specific reason , unless you know the reason for rules don't modify

Is there any whay to know if one rule is in use or not?

check source subnets , destination subnets ,ports , access details as per rules , if subnets are still valid definitely it is in use
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card