Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Reporting Tools?

Status
Not open for further replies.

kfriend

MIS
Feb 10, 2003
50
US
Hello,

I'm wondering if anyone has come across a tool that not only logs events, but also displays the hit-count on the access lists?

The only way I can see now is to print out my current configuration, and login to the pix, and view each line for number of hits and mark on my sheet.

The reason I ask is because I have BIG ACCESS LISTS...really big. And I'd like to keep it managed as good as possible, by removing the ALLOW entries that are not being used.

MCSE/MCDBA
SANS GIAC + SANS FIREWALL
 
Haven't come across anything that does this. Forgive me if you knew this, but you can clear the hit counter on access-lists. Might make it easier to look for 0's on a daily basis rather than log changes. The command for an access-list named "outbound" would be:
clear access-list outbound counters

Just make sure you put the keyword "counts" at the end! :)
 
this is an internal firewall that we use to restrict access to employees. =)
I like the hit counters, because it allows me to see which rules haven't been used since we deployed the pix.

It's about time to scrub the list...right now I have over 1400 lines in my pix config!!!

MCSE/MCDBA
SANS GIAC + SANS FIREWALL
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top