On Thu, May 10, 2012 at 2:51 PM, Dj <[email protected]> wrote: > tcpdump on the server shows the connection coming from the problem agent, > but no reply from the server. > > Nothing in the ossec.log - I did delete the old profile. > > Does anyone know why tcpdump would not see traffic leaving the system to a > particular IP? I was curious and I tried pinging the address and tcpdump > did not see the attempts! The same tcpdump command for another IP address > showed the traffic attempts outbound. >
Did the pings succeed? Are there multiple active network cards in the server? > > > On Thursday, May 10, 2012 1:29:05 PM UTC-4, dan (ddpbsd) wrote: >> >> On Thu, May 10, 2012 at 1:17 PM, Dj <[email protected]> wrote: >> > The VMware host that our OSSEC guest server was running on recently >> > crashed >> > and ever since the crash one of our agents is not connecting to the >> > OSSEC >> > server. >> > >> > Here is what I have attempted for troubleshooting - >> > >> > Created a new agent profile on the Server, extracted the key and >> > configured >> > the agent with the new key. When this was performed, the server reports >> > that the agent has never connected to the OSSEC server. >> > Ran tcpdump on the server to see if the traffic was getting to the >> > server on >> > port 1514 since the remote agent is on another network with a firewall >> > between. This agent was working before the VMware host crash. The >> > tcpdump >> > output shows the UDP traffic getting to the server, but the server is >> > not >> > responding to the agent. >> > Ran tcpdump on the server for another agent that is on a different >> > subnet >> > and results show traffic to the server and back to the agent from the >> > server. >> > >> > Could there be something on the server that is preventing the server >> > from >> > responding to the agent's connection since the UDP traffic from the >> > agent >> > was seen in the tcpdump capture on the server, but no response was >> > detected >> > in the tcpdump capture? >> > >> > Are there any debug settings I can enable to try and see further what is >> > happening on the server? >> > >> > We are running OSSEC 2.6 on the server and the agent. >> > >> > >> > >> > >> > >> >> It sounds like you're blocking the traffic back. Run tcpdump on the >> server, does it see the traffic from the problematic agent? Do you see >> reply traffic from the server? >> >> I'm guessing that there's nothing in ossec.log on the server about >> this agent. Did you delete the old profile for this agent? >> >> Enable debug mode: >> /var/ossec/bin/ossec-control enable debug && >> /var/ossec/bin/ossec-control restart
