Hi all,

I have recently upgraded a firewall I manage from CentOS 4.x to Ubuntu
10.04 based system, I have installed the latest from repos Shorewall
and the latest Ossec 2.5.1.

Under the old system drops and redirects were logged and Ossec would
report them to me via email. Now this does not happen. I can see the
Shorewall entries in the /var/log/messages file as expected but Ossec
will not report them to me. I now have 2 servers that do the same
thing. I have attached entries from one firewall that is working and
one that does not.

This one is working:

Oct 27 10:07:20 gateway kernel: Shorewall:loc2all:ACCEPT:IN=eth1
OUT=XXX SRC=XXX.XXX.XXX.XXX DST=XXX.XXX.XXX.XXX LEN=78 TOS=0x00
PREC=0x00 TTL=63 ID=22537 PROTO=UDP SPT=XXX DPT=XXX LEN=58

This in CentOS 4.X with Ossec 2.4.1

This one is not:

Oct 27 10:08:12 localhost kernel: [139017.036739]
Shorewall:loc2fw:ACCEPT:IN=eth1 OUT=
MAC=---------------------------------------- SRC=xxx.xxx.xxx.xxx
DST=xxx.xxx.xxx.xxx LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=29371 DF
PROTO=TCP SPT=40876 DPT=3128 WINDOW=5840 RES=0x00 SYN URGP=0

This one is on Ubuntu 10.04 with Ossec 2.5.1

Could the [139017.036739] in the second entries be the issue and the
decoder regx is getting confused? I though that Ossec looked for the
program in the 3 field? Sorry if that is way off base?

Thanks for any help you can provide.

Rich

Reply via email to