On Fri, Aug 31, 2012 at 2:39 PM, Leonardo Bacha Abrantes
<
leon...@lbasolutions.com> wrote:
> sorry Dan,
>
> I was testing active response. The ossec server was configured and then used
> nessus to scan my servers to test it.
>
> so, in one server the active response added a iptables rule to block a
> source ip, so, I deleted this rule manually: iptables -D INPUT 1, and
> restarted the server.
> I run nessus against the machine above, and appear in log:
>
> Fri Aug 31 15:31:30 BRT 2012 Unable to run (iptables returning != 2): 6 -
> /var/ossec/active-response/bin/firewall-drop.sh delete - UNKNOWN
> 1346435873.1919331 5706
> ----
> I tested on other server and active response worked and now, i tested again
> in another server and I received the same message.
>
> :(
>