Any one set up a policy to allow Ossec (host-based intrusion detection software) traffic from one zone to another? Currently only ICMP and syslog traffic is allowed, but UDP override is set to allow traffic on the Ossec port. Is this the correct use of the UDP override?
Solved! Go to Solution.
Oh wait, did you mean you did 'Override ports' in the rule and put UDP/1514 there? I would just create a new application on UDP/1514 and put that into the rule instead of doing 'Override ports' in the rule itself.
Note: This is a Sidewinder firewall
Moved to Sidewinder
Moderator
Oh wait, did you mean you did 'Override ports' in the rule and put UDP/1514 there? I would just create a new application on UDP/1514 and put that into the rule instead of doing 'Override ports' in the rule itself.
You create a rule for the traffic on the port which the application uses, from the source zone to the dest zone.
What is UDP override? Is that some OSSec setting?
Thanks. That's what I did.
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA