cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1431
Views
0
Helpful
2
Replies

unused/idle/inactive ASA 8.4 rules

bghobadi2
Level 1
Level 1

Hello,

I have a pair of ASA 5540 running 8.4 code. The firewall set has about 4500 rules. I am tasked to identify all unused/idel/inactive rules in the past 3 months .

Would any one know of a quick way (CLI or CSM) to identify or list such rules? I will grateful for any tip?

Thanks

Bo                 

2 Replies 2

Jennifer Halim
Cisco Employee
Cisco Employee

Check for the rule with hitcount of 0, if the access-list hitcount has never been cleared for a long time or the ASA hasn't been reloaded for a while, then ACL with hitcount of 0 is a clear indication that it has been inactive or not used.

fb_webuser
Level 6
Level 6

We featured this question on our Facebook page. Check out some of the responses here. http://www.facebook.com/CiscoSupportCommunity/posts/426400164068512

---

Posted by WebUser Cisco NetPro from Cisco Support Community App

Review Cisco Networking for a $25 gift card