Troubleshooting commands

Lists the key troubleshooting commands with their purpose for analyzing access rule expansion issues.

Run these commands in the appropriate diagnostic or privileged execution mode on the device.

Command

Purpose

show memory

Provides available, used, and total memory and the free-memory percentage.

Run the command from system support diagnostic-cli mode on the device.

show access-list element-count

Provides current Access Control Entry and access control list counts.

Collect this information when the validation issue occurs.

show object-group count

Provides object-group usage, including IPv4 and IPv6 object counts.

Collect this information along with policy and device details.

show asp table network-object count

Provides source and destination network-object counts.

Use this command for Object Group Search-related sizing.

show dns fqdn-stats

Provides fully qualified domain name distribution and names in the training troubleshooting flow.