官术网_书友最值得收藏!

How it works...

The simple configuration options we've specified for our server simply enable the secure communication over the UDP port 1514 between OSSEC clients and the server. We also configured the server to accept connections from our internal networks.

The best practice is to whitelist any IP addresses of potential agents as well as any known external business-critical resources. By whitelisting critical resources, we can ensure that OSSEC never interrupts service to those resources. Any resource that is critical in an emergency should be whitelisted, which is why we have whitelisted the external mail server.

Imagine being under attack and suddenly losing access to e-mail! The last two blocks configure OSSEC to send an e-mail on our network. If we need a specific SMTP server, we can tweak it here. Once we have our e-mail configured, we establish the thresholds for alerting at events whose level is 7 or higher. We will log any events whose level is 1 or higher.

主站蜘蛛池模板: 海门市| 河间市| 广宗县| 横山县| 庄浪县| 石城县| 神池县| 安龙县| 梨树县| 澄迈县| 萨嘎县| 金秀| 三门峡市| 从化市| 渝中区| 茂名市| 北流市| 商洛市| 景洪市| 永济市| 铜鼓县| 新安县| 随州市| 偃师市| 兰考县| 金寨县| 全州县| 贡山| 海城市| 新乐市| 论坛| 临洮县| 镇巴县| 平利县| 平邑县| 霍州市| 仙居县| 丹东市| 龙岩市| 顺昌县| 荃湾区|