Skip to content
Discussion options

You must be logged in to vote

Ha, okay. So I did a fresh install, ran all the steps I did last time and it still didn't work at first.
Even though the IPtables chain looks good, I think I might have discovered the issue. I'll know shortly if this is the case and will update for sure if this was cause.

What I did different was with the sophos integration, by default it said it would listen on "localhost". I changed this to 0.0.0.0.

Okay, this appears to be the issue. I guess I should have seen this issue sooner, however it doesn't make sense to have the sophos integration bind to localhost only and only receive syslog data from the securityonion node itself since the SO node is not an XG firewall. Also, the netstat out…

Replies: 2 comments 6 replies

Comment options

You must be logged in to vote
5 replies
@dohabandit
Comment options

@dougburks
Comment options

@dohabandit
Comment options

@dohabandit
Comment options

Answer selected by dohabandit
@dougburks
Comment options

Comment options

You must be logged in to vote
1 reply
@dougburks
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants