cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
johnsrs
Level 8
Report Inappropriate Content
Message 1 of 6

Ossec Policy for interzone connection

Jump to solution

Any  one set up a policy to allow Ossec (host-based intrusion detection software) traffic from one zone to another?  Currently only ICMP and syslog traffic is allowed, but UDP override is set to allow traffic on the Ossec port.  Is this the correct use of the UDP override? 

1 Solution

Accepted Solutions
sliedl
Level 14
Report Inappropriate Content
Message 4 of 6

Re: Ossec Policy for interzone connection

Jump to solution

Oh wait, did you mean you did 'Override ports' in the rule and put UDP/1514 there?  I would just create a new application on UDP/1514 and put that into the rule instead of doing 'Override ports' in the rule itself.

View solution in original post

5 Replies
johnsrs
Level 8
Report Inappropriate Content
Message 2 of 6

Re: Ossec Policy for interzone connection

Jump to solution

Note:  This is a Sidewinder firewall

Re: Ossec Policy for interzone connection

Jump to solution

Moved to Sidewinder

Moderator

sliedl
Level 14
Report Inappropriate Content
Message 4 of 6

Re: Ossec Policy for interzone connection

Jump to solution

Oh wait, did you mean you did 'Override ports' in the rule and put UDP/1514 there?  I would just create a new application on UDP/1514 and put that into the rule instead of doing 'Override ports' in the rule itself.

View solution in original post

sliedl
Level 14
Report Inappropriate Content
Message 5 of 6

Re: Ossec Policy for interzone connection

Jump to solution

You create a rule for the traffic on the port which the application uses, from the source zone to the dest zone.

What is UDP override?  Is that some OSSec setting?

johnsrs
Level 8
Report Inappropriate Content
Message 6 of 6

Re: Ossec Policy for interzone connection

Jump to solution

Thanks.  That's what I did.

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community