cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1528
Views
10
Helpful
6
Replies

Disable rule with 0 hits is safe?

marcio.tormente
Level 4
Level 4

Hello guys!

 

I have a firewall with more tham 1500 rules and a lot of then have 0 hits.

I would like to clean the configuration, but I'm noob with firewall and i don´t know if is safe to delete all rules thar there is no hits?

 

Thanks

Marcio

6 Replies 6

akumarka
Cisco Employee
Cisco Employee
no its not safe . hits shows traffic flow .. 0 hits does not means they don't need that access .
it just means no traffic as of now.

Hello Akumarka,

 

How can I make sure that one rule is not in use to be deleted?

 

Thanks

u can clean multiple entry .for example
if u have supersubnet for specific smaller subnet than u can cleanup smaller subnets .only if rule are same

if u changed subnets for site or access changed , you want to restrict some specific subnets then you can clean up unwanted the rules .

mainly rules are already there for specific reason , unless you know the reason for rules don't modify

Is there any whay to know if one rule is in use or not?

check source subnets , destination subnets ,ports , access details as per rules , if subnets are still valid definitely it is in use
Review Cisco Networking products for a $25 gift card