In a multi-sensor environment, you may see agents showing up on sensors that aren’t local to the office where the sensor is deployed.
To fix such a scenario you need to add IPTable entries for each sensor (you can also block this at the firewall as an alternative).
Go to https://dsap.netwatcher.com/sensor and choose the sensor you need to configure
Choose the ‘Edit IPTables Settings’ button
- Create an entry for TCP 9443 and specify the source for the subnet.
- If you have more than 1 subnet make more than 1 entry
- Do this for each sensor
- So now instead of allowing any agent to verify the presence of any sensor, the sensor will only accept agents talking to it from the listed subnets.
Comments