Jump to content


Photo

How to find unused rules in NG F firewalls


  • Please log in to reply
8 replies to this topic

#1 vr

vr
  • Members
  • 1 posts

Posted 21 June 2017 - 01:26 PM

Hi , I just want to find the unused rules in the access rules list. How can i find? is there any feature in the firewalls which shows unused rules for specific time frame?



#2 Alexander Heiss

Alexander Heiss
  • Members
  • 51 posts
  • LocationInnsbruck - Austria

Posted 22 June 2017 - 01:55 AM

Yeah, look here:

https://campus.barra...60000000IOE8AAO



#3 Micha Knorpp

Micha Knorpp
  • Members
  • 173 posts
  • LocationGermany, BW

Posted 23 June 2017 - 03:29 AM

I was wondering about this feature too. But to be honest, I don´t get a clue from the referenced KB article.

Nothing relevant seems to happen if I run that cronjob and "reload Externals".

So where can I view the information that is generated as usage statistics?


regards,
-micha-

#4 Alexander Heiss

Alexander Heiss
  • Members
  • 51 posts
  • LocationInnsbruck - Austria

Posted 26 June 2017 - 03:16 AM

In your Access Ruleset rightmost you should have a column "Usage", when the CC got the data from the Firewalls and you do a "Reload Externals" this column should fill with data.

Example: 0 days (2000)

-> So you know it is a aktiv used rule, because the last time it was used was today, with a count of 2000 (but I am not sure when it resets this counter so use this information with care).

 

Other Example: 30 days (1) or a empty field

-> Maybe Old Rule, used only 1 time OR it could also be a Connection, that was establish 30 days ago and is still connected and used.

 

So It is may a useful Information, but my advise, always double check bevor you delete ;)



#5 Tim Shidal

Tim Shidal
  • Members
  • 28 posts
  • LocationFort Worth, Texas

Posted 26 June 2017 - 08:10 AM

What if you do not use a CC but just have an NG deployed?



#6 Alexander Heiss

Alexander Heiss
  • Members
  • 51 posts
  • LocationInnsbruck - Austria

Posted 26 June 2017 - 11:03 AM

Same, but you don't need to collect the data. You only need "Reload Externals".



#7 Tim Shidal

Tim Shidal
  • Members
  • 28 posts
  • LocationFort Worth, Texas

Posted 26 June 2017 - 11:45 AM

Same, but you don't need to collect the data. You only need "Reload Externals".

Thanks. This worked for my environment - I appreciate the help.



#8 Micha Knorpp

Micha Knorpp
  • Members
  • 173 posts
  • LocationGermany, BW

Posted 27 June 2017 - 05:56 AM

Thanks Alexander,

that´s great indeed.

To be honest: the KB article should be a little bit more specific.... Without your help, I would have never figured this out.

I knew this funcionality is there but never got far (and always forgot to ask).


regards,
-micha-

#9 Guenter Pekar

Guenter Pekar
  • Members
  • 3 posts

Posted 25 September 2018 - 06:40 AM

Hi!

 

Is there a way to reset/clear the Usage column counter?

 

Best regards!