Skip to content
Notifications
Clear all

How do I track which rules are never, ever hit?

1 Posts
1 Users
0 Reactions
3 Views
(@devops_dad)
Estimable Member
Joined: 5 months ago
Posts: 131
Topic starter   [#1502]

Alright, who's been cleaning up their rule base? 🙋‍♂️ I've been there, staring at a firewall policy that's grown over the years like a digital jungle. You inherit it, you add to it, and before you know it, you've got hundreds of rules and a sneaking suspicion half of them are just... decorative.

The question on the table is a good one: how do you find the rules that are collecting digital dust in Firepower? The ones that have never, ever fired a shot in anger. It's not just about tidinessβ€”it's about reducing your attack surface and maybe even getting some performance back.

In the old ASA days, you could lean on the `show asp drop` or some creative logging. With Firepower Management Center (FMC), the path is through **hit counts**. But they're not always on by default for every policy. Here's the quick and dirty:

1. **Enable Hit Counts on Your Access Policy:** In your FMC, go to **Policies > Access Control > Your_Policy**. Click the 'Settings' cog (usually top right). Make sure "**Enable rule state for network analysis**" and "**Log at Beginning of Connection**" are checked for the rules you want to track. The hit counts feed off the connection events.
2. **Let it Bake:** Give it a week or a month of normal traffic. You need a decent sample size.
3. **The Harvest:** Go to **Analysis > Policies > Access Control Rule Hits**. You can filter by device and time range. Sort by hit countβ€”those glorious zeros are your prime candidates for retirement.

A quick story: last year I cleaned up a policy for a client and found a rule allowing RDP from "any" to an old server IP that was decommissioned three years prior. Zero hits for over a year. It was a silent liability.

A word of caution, though. Before you delete, check if any rules are seasonal (like for year-end financial systems) or for rarely-used-but-critical emergency services. Cross-reference with any change tickets you have.

Anyone else have a different method or a tale of what they found in their rulebase graveyard? Ever been burned by removing a "dead" rule?

-- Dad


it worked on my machine


   
Quote