On Thu, May 10, 2012 at 2:51 PM, Dj <[email protected]> wrote:
> tcpdump on the server shows the connection coming from the problem agent,
> but no reply from the server.
>
> Nothing in the ossec.log - I did delete the old profile.
>
> Does anyone know why tcpdump would not see traffic leaving the system to a
> particular IP?  I was curious and I tried pinging the address and tcpdump
> did not see the attempts!  The same tcpdump command for another IP address
> showed the traffic attempts outbound.
>

Did the pings succeed? Are there multiple active network cards in the server?

>
>
> On Thursday, May 10, 2012 1:29:05 PM UTC-4, dan (ddpbsd) wrote:
>>
>> On Thu, May 10, 2012 at 1:17 PM, Dj <[email protected]> wrote:
>> > The VMware host that our OSSEC guest server was running on recently
>> > crashed
>> > and ever since the crash one of our agents is not connecting to the
>> > OSSEC
>> > server.
>> >
>> > Here is what I have attempted for troubleshooting -
>> >
>> > Created a new agent profile on the Server, extracted the key and
>> > configured
>> > the agent with the new key.  When this was performed, the server reports
>> > that the agent has never connected to the OSSEC server.
>> > Ran tcpdump on the server to see if the traffic was getting to the
>> > server on
>> > port 1514 since the remote agent is on another network with a firewall
>> > between.  This agent was working before the VMware host crash.  The
>> > tcpdump
>> > output shows the UDP traffic getting to the server, but the server is
>> > not
>> > responding to the agent.
>> > Ran tcpdump on the server for another agent that is on a different
>> > subnet
>> > and results show traffic to the server and back to the agent from the
>> > server.
>> >
>> > Could there be something on the server that is preventing the server
>> > from
>> > responding to the agent's connection since the UDP traffic from the
>> > agent
>> > was seen in the tcpdump capture on the server, but no response was
>> > detected
>> > in the tcpdump capture?
>> >
>> > Are there any debug settings I can enable to try and see further what is
>> > happening on the server?
>> >
>> > We are running OSSEC 2.6 on the server and the agent.
>> >
>> >
>> >
>> >
>> >
>>
>> It sounds like you're blocking the traffic back. Run tcpdump on the
>> server, does it see the traffic from the problematic agent? Do you see
>> reply traffic from the server?
>>
>> I'm guessing that there's nothing in ossec.log on the server about
>> this agent. Did you delete the old profile for this agent?
>>
>> Enable debug mode:
>> /var/ossec/bin/ossec-control enable debug &&
>> /var/ossec/bin/ossec-control restart

Reply via email to