Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix firewall rules - Cisco Devices - (PR v3.12) #553

Draft
wants to merge 3 commits into
base: master
Choose a base branch
from

Conversation

h0rv4th
Copy link

@h0rv4th h0rv4th commented Jan 30, 2020

Fixes #208

Hello team,
The firewall drop rules aren't working for Cisco devices, because they have deny action instead of drop.

Here are some samples for Cisco devices.

3924923: *Oct  6 03:32:04.114 gmt: %SEC-6-IPACCESSLOGP: list bcv_out denied tcp 10.0.3.100(50150) -> 192.168.216.1(443), 1 packet 

Oct 03 2018 17:34:08: %ASA-4-106023: Deny udp src office:1.1.1.1/3217 dst FE_xUI:Server_Windows/15000 by access-group "ACLoffice" [0x0, 0x0]

Original PR: #209
Author: @migruiz4

@h0rv4th h0rv4th added the bug label Jan 30, 2020
@h0rv4th h0rv4th added this to In progress in Wazuh 3.12.0 via automation Jan 30, 2020
@vikman90 vikman90 changed the base branch from 3.12 to develop July 31, 2020 12:06
@vikman90 vikman90 changed the base branch from develop to master September 25, 2020 08:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
No open projects
Wazuh 3.12.0
  
In progress
Development

Successfully merging this pull request may close these issues.

None yet

2 participants