There's no other active stuff on that server, that build IPTABLE
rules. Just OSSEC and it is running since two days. It was the very
first time, that this happend to the server since 7 years. So I think,
it was OSSEC Active Response.

Yes, I searched through the active-response.log and found nothing
suspect. :(

Regards,

Oskar

On 20 Aug., 14:05, Andre Pawlowski <[email protected]> wrote:
> Is there any entry in the active-response.log? Are you sure OSSEC
> entered this IPTABLES rule?
>
> Regards
>
> Andre Pawlowski
>
> -------------------------------------------------------------------
>
> When we don't know who to hate, we hate ourselves.
>         -Chuck Palahniuk
>
> On 08/20/2010 09:33 AM, WebOscar.net wrote:
>
> > Good Morning all!
>
> > This morning I had a strange IPTABLES rule, which caused a total
> > blocking of everything coming in or out in the forwarding section.
>
> > System: Here's a OpenVZ Server running, having OSSEC on the Host as an
> > agent. The agent is looking into the Containers Logfiles and usualy
> > reacting in the right way. Suddenly I got a message from my monitoring
> > system, that all Containers on this host are not reacheable anymore.
>
> > I (lucky) could log into the host and found this rule with IPTABLES -L
> > under Chain FORWARD (policy ACCEPT):
>
> > DROP       all  --  anywhere             anywhere
>
> > How can this be?
>
> > I have already inspected all OSSEC-Logs on the Host and on the
> > OSSEC-Server for 'anywhere' or '0.0.0.0' but cannot found a record which
> > could raise such a rule.
>
> > Does anybody know, where this rule is coming from AND how to avoid it?

Reply via email to