Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Reporting Tools?

Status
Not open for further replies.

kfriend

MIS
Feb 10, 2003
50
0
0
US
Hello,

I'm wondering if anyone has come across a tool that not only logs events, but also displays the hit-count on the access lists?

The only way I can see now is to print out my current configuration, and login to the pix, and view each line for number of hits and mark on my sheet.

The reason I ask is because I have BIG ACCESS LISTS...really big. And I'd like to keep it managed as good as possible, by removing the ALLOW entries that are not being used.

MCSE/MCDBA
SANS GIAC + SANS FIREWALL
 
Haven't come across anything that does this. Forgive me if you knew this, but you can clear the hit counter on access-lists. Might make it easier to look for 0's on a daily basis rather than log changes. The command for an access-list named "outbound" would be:
clear access-list outbound counters

Just make sure you put the keyword "counts" at the end! :)
 
this is an internal firewall that we use to restrict access to employees. =)
I like the hit counters, because it allows me to see which rules haven't been used since we deployed the pix.

It's about time to scrub the list...right now I have over 1400 lines in my pix config!!!

MCSE/MCDBA
SANS GIAC + SANS FIREWALL
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top