You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
And I think this should trigger the drop alert, because Cisco devices don't have the ACCEPT, REJECT, DROP actions.
Instead, they have "deny" and "permit"
So the equivalent to DROP would be "deny", and it doesn't match the rule.
Hi team,
while testing some rules, I noticed the decoder cisco-ios-acl can't trigger the firewall drop alerts.
This is a sample of cisco-acl log:
Actually is matching rule 4100
wazuh-ruleset/rules/0060-firewall_rules.xml
Lines 9 to 13 in 09b105a
And I think this should trigger the drop alert, because Cisco devices don't have the ACCEPT, REJECT, DROP actions.
Instead, they have "deny" and "permit"
So the equivalent to DROP would be "deny", and it doesn't match the rule.
wazuh-ruleset/rules/0060-firewall_rules.xml
Lines 15 to 24 in 09b105a
Best regards,
Miguel
The text was updated successfully, but these errors were encountered: