    Ossec Policy for interzone connection


      Any  one set up a policy to allow Ossec (host-based intrusion detection software) traffic from one zone to another?  Currently only ICMP and syslog traffic is allowed, but UDP override is set to allow traffic on the Ossec port.  Is this the correct use of the UDP override?