03-25-2009 03:23 PM
Hi Everyone,
I have 30 Cisco PIX and ASA firewalls. Each Interface has ACLs applied with hundreds of Access Control entries.
I would like to know which ACE are inactive for let say last thirty days and should be removed. Any help?
Additionally Any automated tool for that which can do this job and report which ACE are lying in configuration and not getting any hits and should be removed.
Thanks.
03-26-2009 07:26 AM
The only way I know of (and have done) is to clear the ACL counters, wait 30 days, and remove the ones with no hit counts.
03-26-2009 08:08 AM
Thanks. Any direction on software/tool to examines thousands of ACE on PIX/ASA Firewall?
03-26-2009 08:15 AM
We've only looked at one and it was too expensive.
http://www.skyboxsecurity.com/?CategoryID=163
A google search of "Firewall rule audit" comes up with a few more links.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide