Hello,
this is my todays problem:
Host with ip 10.10.10.1
Jail with ip 10.10.10.9
I installed OSSEC on the the host and the agent on the jail.
The agent can not communicate with the server
this is the agent log.
this is the
I think it's a firewall issue and this is the configuration of pf.
What did I do wrong?
Thanks
Franco
this is my todays problem:
Host with ip 10.10.10.1
Jail with ip 10.10.10.9
I installed OSSEC on the the host and the agent on the jail.
The agent can not communicate with the server
this is the agent log.
Code:
2014/08/28 18:00:55 ossec-agentd: INFO: Trying to connect to server (10.10.10.1:1514).
2014/08/28 18:00:55 ossec-agentd: INFO: Using IPv4 for: 10.10.10.1 .
2014/08/28 18:01:16 ossec-agentd(4101): WARN: Waiting for server reply (not started). Tried: '10.10.10.1'.
netstat -af inet
output.
Code:
Proto Recv-Q Send-Q Local Address Foreign Address (state)
tcp4 0 0 10.10.10.9.15011 10.10.10.1.ssh ESTABLISHED
tcp4 0 0 10.10.10.9.ssh *.* LISTEN
udp4 0 0 10.10.10.9.40368 10.10.10.1.fujitsu-dtc
Code:
ext_if = "re0"
int_if = "em0"
local_net = "10.10.10/24"
web_server = "10.10.10.10"
web_ports = "{ http, https }"
udp_ports ="{ domain, ntp }"
ssh_server = "10.10.10.9"
ssh_port = " ssh "
table <ossec_fwtable> persist #ossec_fwtable
scrub in all
nat on $ext_if from $local_net to any -> $ext_if
rdr on $ext_if proto tcp from any to any port $web_ports -> $web_server
rdr on $ext_if proto tcp from any to any port $ssh_port -> $ssh_server
antispoof log quick for { $ext_if } inet
#block all
block in all
pass on $int_if all
pass out on $ext_if all
set skip on lo0
block in log quick from <ossec_fwtable>
pass quick proto tcp from any to $web_server port $web_ports
pass quick proto tcp from any to $ssh_server port $ssh_port
pass in on $int_if proto udp from $local_net to any port 1514
Thanks
Franco