cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
525
Views
0
Helpful
3
Replies

hits counts for static statements

Kevin Melton
Level 2
Level 2

Is there a command that will display the matches or hit counts that have qualified against a "static" statement on the PIX or ASA?

Thank You

3 Replies 3

Hi Kevin,

Take a look at the output of 'show xlate'. This may give you what you are looking for.

From the ASA 8.0 command reference for 'show xlate':

"The following is sample output from the show xlate command. It shows two static translations. The first translation has one associated connection (called "nconns"), and the second translation has four associated connections."

hostname# show xlate

Global 209.165.201.10 Local 209.165.201.10 static nconns 1 econns 0

Global 209.165.201.30 Local 209.165.201.30 static nconns 4 econns 0

http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/s7.html#wp1263940

Hope that helps.

-Mike

Mike

Thanks for your answer. My dilema is that on this old legacy PIX Firewall, we are currently running only 6.3.4 code. I dont think it has enough memory in it to do very much more than that either.

I thought I had remembered working with a Cisco engineer at some point in the past, and him using a command which showed how many matches there were for successful translations against the STATIC statement. I could be mistaken.

Hi Kevin,

'show xlate' may still give you what you're looking for, so take a look at that. The command reference I posted before applies to PIX 6.3(4) a well, but here it is from the PIX 6.3 command reference as well:

http://www.cisco.com/en/US/docs/security/pix/pix63/command/reference/s.html#wp1084248

-Mike

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: