The same server security policy has been applied to both SRV1 and SRV2 servers.
Warning mode for the HOST class is enabled on both the servers.
However, there are "no P logs were generated on SRV1", while a large number of P logs appeared on SRV2.
Currently, the HOST _default setting is configured with audit(FAILURE) only, and no policy is defined for SUCCESS.
We would like to understand why P logs are being generated on SRV2under these conditions, while SRV1remains unaffected.
They have set audit(fail) for the HOST class record and they establish an incoming connection to the PAMSC endpoint server from an external server whose incoming connection is set to be audited only for failure
The connection is successful from the external machine to the PAMSC endpoint server
The seaudit logs have a P (Permit) log.
As per documentation we should be having a W (Warning) record in the audit logs.
PAMSC : 14.1 CP06
Version of PAMSC :: 14.10.60.129
This has been identified a bug and has now been fixed for CP06 verision mentioned in this article.
The hotfix for this is available. Please open a support ticket requesting the hotfix.
Installing the Patch:
- Unzip the folder
- Run tfinstall.exe
- Once the installation is done, The affected binary will be replaced.
Note: This patch does not have any extra steps to perform.