OSSEC Agents are not Connecting to Different Network Segments

13 views
Skip to first unread message

sunitha s

unread,
Jul 18, 2019, 1:38:54 AM7/18/19
to ossec-list
Hii All,
 
  I Have Installed the OSSEC version 3.1 in Ubuntu 16.04 in My Local PC.
I Have Installed OSSEC Agents in the same Network segment, the Agents are connected and sending logs to OSSEC Server, and also installed agents in different network segments,all the Configuration are done properly(like that agent ip's are pinging,disabled the internal firewall),when i run the command /var/ossec/bin/manage-agents it list down all the agents from the different network segments, But when I am Run the command /var/ossec/bin/agent-control -l it shows the  agent state like "NEVER CONNECTED".


Can Anyone Help Me For Connecting the Agents From the Different Network Segments.

dan (ddp)

unread,
Jul 18, 2019, 7:59:52 AM7/18/19
to ossec...@googlegroups.com
Make sure they aren't communicating by checking for alerts from the
not-connected agents.
Make sure the IP address that the OSSEC server sees the agents as is
the IP configured in manage_agents (no NAT).
Use tcpdump to make sure the traffic from the agent is making it to
the OSSEC server (default: port 1514 udp).
Check the agent's ossec.log for errors.
Check the server's ossec.log for errors.

> --
>
> ---
> You received this message because you are subscribed to the Google Groups "ossec-list" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to ossec-list+...@googlegroups.com.
> To view this discussion on the web visit https://groups.google.com/d/msgid/ossec-list/d239b3dc-bc99-4336-9573-44ead7916a44%40googlegroups.com.
> For more options, visit https://groups.google.com/d/optout.
Reply all
Reply to author
Forward
0 new messages