11-08-2013 08:51 AM - edited 03-11-2019 08:02 PM
ASA Version: 8.2(2)
ASDM Version: 6.2(5)
Device Type ASA 5510
I see hits in the "Top 10 Access Rules" but see nothing in the "Access Rules" page and the CLI. Does this look like a bug or am I missing something? Thanks in advance!
Top 10 Access rules show hits. For e.g. Rule 177, 189, and 190.
The Access Rules page in ASDM does not show any hits but has "Top 10" marked.
The CLI shows no hits for rule 177:
MyASA# show access-list | include 177
access-list outside_access_in line 177 extended permit object-group TCPUDP object-group MyName object-group ActiveDirectoryServers object-group ActiveDirectory 0x0a4449d8
access-list outside_access_in line 177 extended permit udp 10.14.7.0 255.255.255.0 10.100.100.0 255.255.255.0 eq 389 (hitcnt=0) 0xa44bd570
access-list outside_access_in line 177 extended permit udp 10.14.7.0 255.255.255.0 10.100.100.0 255.255.255.0 eq 445 (hitcnt=0) 0x4c0d225b
access-list outside_access_in line 177 extended permit udp 10.14.7.0 255.255.255.0 10.100.100.0 255.255.255.0 eq 88 (hitcnt=0) 0xda11f206
access-list outside_access_in line 177 extended permit udp 10.14.7.0 255.255.255.0 10.100.100.0 255.255.255.0 eq domain (hitcnt=0) 0xadb35eeb
access-list outside_access_in line 177 extended permit udp 10.14.7.0 255.255.255.0 10.100.100.0 255.255.255.0 eq ntp (hitcnt=0) 0x54e1942c
access-list outside_access_in line 177 extended permit udp 10.14.7.0 255.255.255.0 10.100.100.0 255.255.255.0 eq 3268 (hitcnt=0) 0x4815484d
access-list outside_access_in line 177 extended permit udp 10.14.7.0 255.255.255.0 10.100.100.0 255.255.255.0 eq 135 (hitcnt=0) 0x4ee5e504
access-list outside_access_in line 177 extended permit udp 10.14.7.0 255.255.255.0 10.100.100.0 255.255.255.0 range 1025 1026 (hitcnt=0) 0x78c1a00a
access-list outside_access_in line 177 extended permit udp 10.14.7.0 255.255.255.0 10.100.100.0 255.255.255.0 eq www (hitcnt=0) 0x547c7f3f
access-list outside_access_in line 177 extended permit udp 10.14.7.0 255.255.255.0 10.100.100.0 255.255.255.0 eq 139 (hitcnt=0) 0x675a8434
access-list outside_access_in line 177 extended permit udp 10.14.7.0 255.255.255.0 10.100.100.0 255.255.255.0 range 49152 49200 (hitcnt=0) 0x041ee127
access-list outside_access_in line 177 extended permit tcp 10.14.7.0 255.255.255.0 10.100.100.0 255.255.255.0 eq ldap (hitcnt=0) 0xefd4becb
access-list outside_access_in line 177 extended permit tcp 10.14.7.0 255.255.255.0 10.100.100.0 255.255.255.0 eq 445 (hitcnt=0) 0x22c6df99
access-list outside_access_in line 177 extended permit tcp 10.14.7.0 255.255.255.0 10.100.100.0 255.255.255.0 eq 88 (hitcnt=0) 0x6c69d270
access-list outside_access_in line 177 extended permit tcp 10.14.7.0 255.255.255.0 10.100.100.0 255.255.255.0 eq domain (hitcnt=0) 0x958ad172
access-list outside_access_in line 177 extended permit tcp 10.14.7.0 255.255.255.0 10.100.100.0 255.255.255.0 eq 123 (hitcnt=0) 0x004630da
access-list outside_access_in line 177 extended permit tcp 10.14.7.0 255.255.255.0 10.100.100.0 255.255.255.0 eq 3268 (hitcnt=0) 0x3b13d00e
access-list outside_access_in line 177 extended permit tcp 10.14.7.0 255.255.255.0 10.100.100.0 255.255.255.0 eq 135 (hitcnt=0) 0x98307d89
access-list outside_access_in line 177 extended permit tcp 10.14.7.0 255.255.255.0 10.100.100.0 255.255.255.0 range 1025 1026 (hitcnt=0) 0xd1d12d12
access-list outside_access_in line 177 extended permit tcp 10.14.7.0 255.255.255.0 10.100.100.0 255.255.255.0 eq www (hitcnt=0) 0x46d6d2ed
access-list outside_access_in line 177 extended permit tcp 10.14.7.0 255.255.255.0 10.100.100.0 255.255.255.0 eq netbios-ssn (hitcnt=0) 0x20a6e7bf
access-list outside_access_in line 177 extended permit tcp 10.14.7.0 255.255.255.0 10.100.100.0 255.255.255.0 range 49152 49200 (hitcnt=0) 0x15dbf9ad
11-11-2013 02:07 PM
This does sound a lot like a bug, though I have not been able to find any bug reports about it. If it is an option, try upgrading the ASA and ASDM to a slightly newer version.
11-15-2013 10:44 AM
Were you able to upgrade the ASA and ASDM? did this solve the issue?
Please rate any helpful posts.
11-17-2013 01:53 PM
http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=%20CSCsl30904
11-17-2013 01:57 PM
https://tools.cisco.com/bugsearch/bug/CSCtj67289/?reffering_site=dumpcr
Please update your ASDM version to 7.1.4
11-18-2013 08:51 PM
Please rate the assistance
11-19-2013 10:49 AM
Do you still require assistance with this ticket? If not please rate all helpful posts
11-19-2013 12:45 PM
Help is for free then we need you to rate the assistance.
11-20-2013 11:41 AM
Help is for free but we need you to rate the assistance.
11-20-2013 11:49 AM
Hello. My apologies for the delay. I was off work for a few days. Just got back into the office today. Please give me some time to read/research the replies. I will add my ratings.
11-20-2013 12:18 PM
Bug CSCsl30904 matches up with what I see.
Bug CSCtj67289 does not match up with my issue.
I will install the new ASDM 7.1.4 in the next few days and provide an update.
11-20-2013 03:26 PM
Bug CSCsl30904 shows Known Fixed Releases: 6.0(3.50) and 6.1(0.35). I am on ASA Version: 8.2(2) and ASDM Version: 6.2(5).
I will upgrade the ASDM version to 7.1.4, but I think this requires an ASA upgrade to truly fix, as I am seeing the same zero counters in the CLI.
11-20-2013 11:41 PM
Let us know how it goes,
--
Please rate all helpful posts
12-19-2013 01:11 PM
This functionality is still broken in ASA 8.3(2) and ASDM 7.1(4). The Access Rules hits are still showing 0, but the Top 10 shows valid hits. The CLI also shows 0 hits.
access-list outside_access_in line 29 extended permit ip object-group SaabTestASA object-group Q-LAN 0x5cc09292
access-list outside_access_in line 29 extended permit ip 10.140.50.0 255.255.255.0 10.100.0.0 255.255.0.0 (hitcnt=0) 0x688c7eb7
access-list outside_access_in line 29 extended permit ip 10.140.50.0 255.255.255.0 172.20.1.0 255.255.255.0 (hitcnt=0) 0x0e1cdb8a
access-list outside_access_in line 29 extended permit ip 10.140.50.0 255.255.255.0 10.40.40.0 255.255.255.0 (hitcnt=0) 0x32c8018e
access-list outside_access_in line 29 extended permit ip 10.140.50.0 255.255.255.0 10.130.0.0 255.255.0.0 (hitcnt=0) 0xdc32b863
access-list outside_access_in line 29 extended permit ip 10.140.50.0 255.255.255.0 10.140.0.0 255.255.0.0 (hitcnt=0) 0x88bbd947
access-list outside_access_in line 29 extended permit ip 10.140.50.0 255.255.255.0 10.150.0.0 255.255.0.0 (hitcnt=0) 0x1c21f374
access-list outside_access_in line 29 extended permit ip 10.140.50.0 255.255.255.0 172.16.125.0 255.255.255.0 (hitcnt=0) 0x5cc1b4df
access-list outside_access_in line 29 extended permit ip 10.140.50.0 255.255.255.0 130.94.124.0 255.255.255.192 (hitcnt=0) 0xf60a4f68
access-list outside_access_in line 29 extended permit ip 10.140.50.0 255.255.255.0 10.120.0.0 255.255.0.0 (hitcnt=0) 0x9af079b2
12-19-2013 01:18 PM
I will proceed to try 8.4 and 9.1 in th next few days or weeks. Hopefully the newer releases give me better results.
Happy Holidays to everyone!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide