Ok, I have installed -devel branch in this agent and all works as expected ... Really strange ... I will install another FreeBSD host tomorrow and I will see ...
On Wed, Apr 10, 2013 at 12:36 PM, dan (ddp) <ddp...@gmail.com> wrote: > On Wed, Apr 10, 2013 at 1:51 AM, C. L. Martinez <carlopm...@gmail.com> > wrote: > > Here it is: > > > > I put this rc.conf in place (/etc/rc.conf) on my FreeBSD 9.1 system, > deleted all previous remnants of OSSEC, and ran install.sh from a > fresh untarring of the latest source. Everything worked as expected. > > Can you please provide more information on what you're doing? Maybe > use script to copy the installation process (you can gzip the output > and send it to me privately if you want). > > > > root@plzfsiem02:/etc/mail# more /etc/rc.conf > > ############################################################## > > ### Important initial Boot-time options #################### > > ############################################################## > > > > rc_conf_files="/etc/rc.conf /etc/rc.conf.local" > > dumpdev="NO" > > > > > > ############################################################## > > ### System general options ################################# > > ############################################################## > > > > keymap="spanish.iso15.acc.kbd" > > clear_tmp_enable="YES" > > > > > > ############################################################## > > ### Network configuration sub-section ###################### > > ############################################################## > > > > hostname="fbsd.domain.com" > > defaultrouter="10.196.0.1" > > ifconfig_em0="inet 10.196.0.104 netmask 255.255.255.0" > > ifconfig_em1="inet 172.17.22.2 netmask 255.255.255.248" > > ifconfig_em2="inet 172.17.23.2 netmask 255.255.255.248" > > ipv4_addrs_em0="10.196.0.93/32" > > > > > > ### Enable PF firewall ### > > pf_enable="YES" > > pf_rules="/etc/pf.conf" > > pflog_enable="YES" > > pflog_logfile="/var/log/pflog" > > pflog_flags="-s 256" > > > > > > ### Network daemon (miscellaneous) ### > > > > .... > > > > > > On Tue, Apr 9, 2013 at 4:25 PM, C. L. Martinez <carlopm...@gmail.com> > wrote: > >> > >> Thanks Dan. Sure, I will send you tomorrow ... > >> > >> > >> On Tue, Apr 9, 2013 at 3:56 PM, dan (ddp) <ddp...@gmail.com> wrote: > >>> > >>> On Tue, Apr 9, 2013 at 8:13 AM, dan (ddp) <ddp...@gmail.com> wrote: > >>> > On Tue, Apr 9, 2013 at 2:39 AM, C. L. Martinez <carlopm...@gmail.com > > > >>> > wrote: > >>> >> Ok, I have reinstalled ossec client and same problem ... It is > >>> >> searching > >>> >> ipfilter ... > >>> >> > >>> >> > >>> > > >>> > All right. I'm downloading FreeBSD now. > >>> > > >>> > > >>> > >>> > >>> I was unable to reproduce this issue. I installed FreeBSD, added > >>> 'pf_enable="YES"' to /etc/rc.conf, started the pf service stuff, and > >>> then installed OSSEC. The correct script was installed at > >>> /var/ossec/active-response/bin/firewall-drop.sh. > >>> > >>> Can you provide your rc.conf? Maybe looking at that will help. > >>> > >>> -- > >>> > >>> --- > >>> You received this message because you are subscribed to the Google > Groups > >>> "ossec-list" group. > >>> To unsubscribe from this group and stop receiving emails from it, send > an > >>> email to ossec-list+unsubscr...@googlegroups.com. > >>> For more options, visit https://groups.google.com/groups/opt_out. > >>> > >>> > >> > > > > -- > > > > --- > > You received this message because you are subscribed to the Google Groups > > "ossec-list" group. > > To unsubscribe from this group and stop receiving emails from it, send an > > email to ossec-list+unsubscr...@googlegroups.com. > > For more options, visit https://groups.google.com/groups/opt_out. > > > > > > -- > > --- > You received this message because you are subscribed to the Google Groups > "ossec-list" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to ossec-list+unsubscr...@googlegroups.com. > For more options, visit https://groups.google.com/groups/opt_out. > > > -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to ossec-list+unsubscr...@googlegroups.com. For more options, visit https://groups.google.com/groups/opt_out.