On Wed, Jan 30, 2013 at 10:56 AM, Taylor Swartz <[email protected]> wrote: > But does that give OSSEC the ability to drop the firewall rule after the > expiration of the event? >
No idea, I don't generally care about unblocking. > On Wednesday, January 30, 2013 9:22:44 AM UTC-6, dan (ddpbsd) wrote: >> >> On Wed, Jan 30, 2013 at 10:07 AM, Taylor Swartz <[email protected]> wrote: >> > Is there a way to set OSSEC to restore all of the active rules, >> > including >> > iptables, on restart of the ossec server? >> > >> >> Not really. I just have my systems save the firewall settings and >> configure it on boot. >> >> > -- >> > >> > --- >> > You received this message because you are subscribed to the Google >> > Groups >> > "ossec-list" group. >> > To unsubscribe from this group and stop receiving emails from it, send >> > an >> > email to [email protected]. >> > For more options, visit https://groups.google.com/groups/opt_out. >> > >> > > > -- > > --- > You received this message because you are subscribed to the Google Groups > "ossec-list" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to [email protected]. > For more options, visit https://groups.google.com/groups/opt_out. > > -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/groups/opt_out.
