Security Basics mailing list archives

Re: Tripwire Client thru a G2 Firewall


From: "Michal Merta" <michal.merta () gmail com>
Date: Thu, 8 Jun 2006 09:53:03 +0200

Hi Mart,

Try to use proxies for these 2 ports, activate it, make the rule.
Later log to G2 via ssh and try:
acat -ae "src_ip client and dst_ip server" (or realtime acat -ake
"src_ip client and dst_ip server")
Can you see some traffic there? (especially at desired ports?)
Michal


On 7 Jun 2006 00:29:36 -0000, aquanuts () gmail com <aquanuts () gmail com> wrote:
 Guys,





I have two sun servers on my DMZ and would like to have tripwire client report system activities back to our tripwire server 
"inside" our network. But, I can not get the server to auto-detect the clients on the DMZ. I have two packet filters 
running, one for port 9898 (by-directional) and the second is for port 8080 (by-directional). I see 9898 traffic, but I never see 
8080 traffic.





Can anyone point out what I'm doing wrong ????





               Mart




--
Michal Merta
Network Security Engineer
http://www.misuta.cz

The information contained in this electronic message and any
attachments to this message are intended for the exclusive use of the
addressee(s) and may contain proprietary, confidential or privileged
information. If you are not the intended recipient, you should not
disseminate, distribute or copy this e-mail. Please notify the sender
immediately and destroy all copies of this message and any
attachments.


Current thread: