On Tue, Jun 14, 2016 at 8:17 AM, Zeal Vora <[email protected]> wrote: > Hi > > We installed OSSEC in our production machines yesterday and today we saw > that all the iptables rules in all the machines were flushed. Something > similar to iptables -F > > Any idea on what can cause this ? I am aware that OSSEC active-response can > add or remove entries from iptables but have never knew about flushing > entire iptables rules. > > Any help will be appreciated.! >
Which version of OSSEC? Is active response enabled? > > -- > > --- > You received this message because you are subscribed to the Google Groups > "ossec-list" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to [email protected]. > For more options, visit https://groups.google.com/d/optout. -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/d/optout.
