[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[ossec-list] Re: Anyone suggest windows Firewall works with ossec?
- To: <ossec-list@xxxxxxxxxxxxxxxx>
- Subject: [ossec-list] Re: Anyone suggest windows Firewall works with ossec?
- From: <deltamails@xxxxxxxxx>
- Date: Wed, 4 Jul 2007 04:30:29 -0700
- Dkim-signature: a=rsa-sha1; c=relaxed/relaxed; d=gmail.com; s=beta; h=domainkey-signature:received:received:message-id:from:to:references:subject:date:mime-version:content-type:content-transfer-encoding:x-priority:x-msmail-priority:x-mailer:x-mimeole; b=bt0ph7Zq/3pzQ4jX/zR3qUifk4P7JAGHf7p9nbjJNum00VP7v09uFsSGd+sn9YdTJe7bL1eUgN1w9fOoCIi/OAF8dNhGBBK9AbLH1F+fYa7Yx6/u1xtIFCztA2+1R3J7XIaakL6kb8gBgT3tiHLMpDP+5f6jc9oUtKsW2WWNz0I=
John,
Windows version of OSSEC is like Read only mode. It can no do something like
active respone which is possible in Linux edition. But Windows is more
vulnerable to brute force and other attacks.
If some firewall and ossec and be married together then it makes perfect
combination. Right now ossec on windows is just reading the logs and sending
alerts.
If anyone have any idea how to implement this then please suggest.
Regards,
DM
----- Original Message -----
From: "John Ives" <jives@xxxxxxxxxxxxxxxxxxxxx>
To: <ossec-list@xxxxxxxxxxxxxxxx>
Sent: Wednesday, July 04, 2007 12:34 AM
Subject: [ossec-list] Re: Anyone suggest windows Firewall works with ossec?
>
> MdMonk wrote:
>> There's talk of how to implement active-response on Microsoft Windows
>> systems. Something I had brought up was to use the "netsh" command.
>>
>> -Chuck (MdMonk)
>>
>> On 7/4/07, deltamails@xxxxxxxxx <deltamails@xxxxxxxxx> wrote:
>>
>>> Can anyone suggest windows firewall that works with ossec?
>>>
>>> Regards,
>>> DM
>>>
>
> I have been considering this as well lately and feel that using netsh to
> manipulate the IPSec filters would be the best bet. My concern has been
> how to write a script that could be used in multiple environments.
> Since only one IPSec policy can be applied at a time, I would guess that
> a config file would be necessary so that admins could set the policy to
> use along with any other settings.
>
> John
>
> --
> -------------------------------------------------------------------------
> John Ives Phone (510) 642-7773
> System & Network Security Cell (510) 229-8676
> University of California, Berkeley
> -------------------------------------------------------------------------
>
>
OSSEC home |
Main Index |
Thread Index
OSSEC project: www.ossec.net.
Mailling list information: http://www.ossec.net/en/mailing_lists.html.