small question :)

how to deal with rules where source address is set like daniel mentioned?
like fw rules / apache rules / ssh rules etc ...

is it possible to only set it to the "host" address if it's not set via
rules?
and what about multi homed "server"? a set to the host address (ossec
address) would alert attacks/events to the wrong interface this could lead
to wrong correlation.

and by the way ossec is not only a hid it's a very good lid ;)
and that's here the problem *g*

just my 2 cent

cheers
philipp

Reply via email to