It can block internal IPs. If you don't want the IP blocked, add it to the white list.
On Mon, Oct 25, 2010 at 10:25 AM, seekuel <[email protected]> wrote: > Dear group, > > We have a dedicated server that is configured to have a multiple public IPs > configured to eth1. What happens is that in /etc/hosts.deny the public IP > addresses are found. Thus this means that ossec blocks internal IP > addresses? > > Please advice > > Thank you > >
