Daniel,

i think you don't understand what i said.

i did all this.

i add table, add rules, add all.

ossec is using the script and in log show the ip and other things, don't
show errors.

but when i show table of PF, the table is clear.
The rules of PF don't block ip because ip is not include in table.


then, the ossec said that ip was added, but the ip is not include in table.


the block using hosts is fine.


do you understand?

OBS: Acho que meu inglês está péssimo hehe, o ossec mostra no log a inclusão
do ip, porém ele não inclui o ip, quando listo os ips da tabela, ela está
limpa, porém ele inclui corretamente no hosts. Se eu mudar o nome da tabela,
da erro, com isso sei que ele está usando a tabela certa, o único erro, é
que o ip não consta na tabela, ou seja, ele diz que faz, mas na realidade
não está fazendo, estou com o mesmo problema em 2 BSDs. tentei corrigir o
script, porém aparentemente está tudo certo, e não consegui identificar nada
fora do ossec que pudesse estar interferindo, por isso estou perguntando
para ver se não era um bug conhecido, desculpe o incomodo. Pode responder em
inglês mesmo ;)



On Tue, Apr 22, 2008 at 12:50 PM, Daniel Cid <[EMAIL PROTECTED]> wrote:

>
> Hi Kivanio,
>
> Did you follow the steps in the configuration for pf?
>
> http://www.ossec.net/main/manual/#active-response-config
>
> "
> On PF, you need to create a table in your config and deny all the
> traffic to it. Add the following lines at the beginning of your
> rules and reload pf (pfctl -F all && pfctl -f /etc/pf.conf):
>
> table <ossec_fwtable> persist #ossec_fwtable
>
> block in quick from <ossec_fwtable> to any
> block out quick from any to <ossec_fwtable>
> "
>
> Thanks,
>
> --
> Daniel B. Cid
> dcid ( at ) ossec.net
>
>
> On Sun, Apr 13, 2008 at 8:50 PM, Kivanio Barbosa <[EMAIL PROTECTED]>
> wrote:
> > Hi Daniel,
> >
> > i see your mensage about ossec 1.5 so i remove ossec 1.4 and install
> 1.5.
> >
> > the same problem happen.
> >
> >
> >
> > server server /usr/local/ossec # tail -f logs/active-responses.log
> > Sun Apr 13 19:42:55 AMT 2008
> > /usr/local/ossec/active-response/bin/host-deny.sh add - 89.13.24.98
> > 1208130175.568 20100
> > Sun Apr 13 19:42:55 AMT 2008
> > /usr/local/ossec/active-response/bin/firewall-drop.sh add - 89.13.24.98
> > 1208130175.568 20100
> > ^C
> > server server /usr/local/ossec # pfctl -t ossec_fwtable -T show
> > server server /usr/local/ossec # cat /etc/hosts.deny
> > ALL:89.48.135.87
> > ALL:89.48.62.163
> > ALL:217.235.146.142
> > ALL:92.228.210.101
> > ALL:91.37.126.196
> > ALL:89.57.6.219
> > ALL:77.181.89.215
> > ALL:79.234.249.31
> > ALL:77.134.83.174
> > ALL:77.178.150.133
> > ALL:217.235.220.210
> > ALL:77.179.187.66
> > ALL:77.183.179.60
> > ALL:87.167.138.240
> > ALL:75.126.23.220
> > ALL:217.232.206.235
> > ALL:77.179.9.47
> > ALL:84.145.5.163
> > ALL:89.13.24.98
> > ALL:79.234.249.31
> > ALL:89.48.62.163
> > ALL:217.235.146.142
> > ALL:89.48.161.32
> > ALL:201.3.34.169
> >
> >
> > The host-deny.sh works fine but firewall-drop.sh don't.
> >
> >
> > --
> > Kivanio Pereira Barbosa
> > Cel 8121-4248
> >
> > www.eiqconsultoria.com.br
>



-- 
Kivanio Pereira Barbosa
Cel 8121-4248

www.eiqconsultoria.com.br

Reply via email to