-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Jun 16, 2011, at 1:59 PM, pierz wrote: > previous thread : > http://groups.google.com/group/ossec-list/browse_thread/thread/340a6367b024c11a/b384ac2f1d514ced?lnk=gst&q=%22%3Clocation%3Eall%22 > > So I configured the active-response like this, to have the AR enable > on both ALL agents and the server (because when you configure only > <location>all</location> it won't block on the server.
So are you trying to have the IP blocked on all servers when triggered from a single server? - --------------------------- Jason 'XenoPhage' Frisvold [email protected] - --------------------------- "Any sufficiently advanced magic is indistinguishable from technology." - - Niven's Inverse of Clarke's Third Law -----BEGIN PGP SIGNATURE----- Version: GnuPG/MacGPG2 v2.0.16 (Darwin) iEYEARECAAYFAk36m0AACgkQ8CjzPZyTUTQqjQCfU94Xvu+xnACE0m43ZyLMTeKb 58gAnjUVVJnfvOg2ePr6A/WAWWhArKW7 =inG1 -----END PGP SIGNATURE-----
