Showing results for 
Search instead for 
Did you mean: 

ASA firewall rules with Zero Hits

Level 1
Level 1

OK, been looking at ASA FW Rules and we have a LOT of rules with Zero Hits. Can I safely remove these? Doing a system cleanup and hit counters have not been cleared for a very long time.

3 Replies 3

@jroy777 yes you should be able to remove these if you are confident they are not required. Before you clear the rules down, take a backup to be on the safe side. I'd also personally just confirm the hit counter are actually increasing on active rules, just in case there might be bug where the hit counters don't work!!

You use syslog  server?

If yes then add log to acl you want to delete' then monitor the log if you dont see any log for one week or more the you can safely remove it.

But as @Rob Ingram  mention take backup of config before start this process.

Level 1
Level 1


I'd recommend using ASDM, which allows you to easily disable rules by unchecking each rule. You can also view when last each rule was hit. You can also get a CSV export for your rules via ASDM.

Review Cisco Networking for a $25 gift card