05-19-2017 08:25 AM - edited 03-12-2019 04:28 AM
Hello All:
Over the years and multiple vendors and projects our ASA Access Rules, Static Routes, NAT entries and VPN tunnels, considerable junk has accumulated. As usual be it a contractor or staff everyone I keen in adding statements but not cleaning up!
Now I have the wonderful task of removing obsolete IPs, NAT and Access. VPN entries.
I used Solarwinds FSM to run analysis but the results were only harping in an alarming manner of the number of any to any entries. I was surprised myself but it appears to be the last statements in a section as a catch all. Cisco ASA configs does not specify best practices to restrict "any to any" use. I am prudent enough not to remove without research and safe step would be to disable and see what happens? !!
Any other less dramatic suggestions to test removal? (Sample attatched)
All suggestions much appreciated.
Thx
SV
Solved! Go to Solution.
05-21-2017 03:13 AM
I tend to look at hit counts to see if rules are being used or not, which of course you would need to run over a longer period of time. then when the rile still shows 0 hitcount after weeks, put it on non active. after a longer period you can decide to delete the rule.
probably the easiest way to clean up.
PLease rate if useful.
05-21-2017 03:13 AM
I tend to look at hit counts to see if rules are being used or not, which of course you would need to run over a longer period of time. then when the rile still shows 0 hitcount after weeks, put it on non active. after a longer period you can decide to delete the rule.
probably the easiest way to clean up.
PLease rate if useful.
05-22-2017 06:58 AM
Thank you very much Appreciate the steps
Regards
SV
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide