Possible firewall issue accessing Elasticsearch #10817
-
Hi, I am accessing Elasticsearch via curl commands. Once I do that, the curl command instantly returns with results, but only for a little while, maybe 5 or 10 minutes, then I have to perform the firewall reload command again. I tried adding the port to the firewall but still after 5 to 10 minutes the curl command fails unless I keep running the firewall reload command. I setup a second Security Onion but ran into the issue again. Am I missing a step? Is there another Security Onion command I need to run? My setup is the SO eval running as a VM. I am accessing it from the host machine with curl commands. Thanks in advance for any time and help. Frank |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments
-
How exactly are you running so-allow? After running so-allow, do you see the firewall rule when you run the following command?
|
Beta Was this translation helpful? Give feedback.
-
Thanks. It was user error. |
Beta Was this translation helpful? Give feedback.
How exactly are you running so-allow?
https://docs.securityonion.net/en/2.3/so-allow.html
After running so-allow, do you see the firewall rule when you run the following command?