diff --git a/salt/wazuh/files/wazuh-manager-whitelist b/salt/wazuh/files/wazuh-manager-whitelist
new file mode 100644
index 000000000..0cf675f5c
--- /dev/null
+++ b/salt/wazuh/files/wazuh-manager-whitelist
@@ -0,0 +1,33 @@
+{%- set MASTERIP = salt['pillar.get']('static:masterip', '') %}
+#!/bin/bash
+#
+# Copyright 2014,2015,2016,2017,2018,2019,2020 Security Onion Solutions, LLC
+#
+# This program is free software: you can redistribute it and/or modify
+# it under the terms of the GNU General Public License as published by
+# the Free Software Foundation, either version 3 of the License, or
+# (at your option) any later version.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program. If not, see .
+
+# Check if Wazuh enabled
+if grep -q -R "wazuh: 1" /opt/so/saltstack/pillar/*; then
+ WAZUH_MGR_CFG="/opt/so/wazuh/etc/ossec.conf"
+ if ! grep -q "{{ MASTERIP }}" $WAZUH_MGR_CFG ; then
+ DATE=`date`
+ sed -i 's/<\/ossec_config>//' $WAZUH_MGR_CFG
+ sed -i '/^$/N;/^\n$/D' $WAZUH_MGR_CFG
+ echo -e "\n \n {{ MASTERIP }}\n \n" >> $WAZUH_MGR_CFG
+ echo "Added whitelist entry for {{ MASTERIP }} in $WAZUH_MGR_CFG."
+ echo
+ echo "Restarting OSSEC Server..."
+ /usr/sbin/so-wazuh-restart
+ fi
+fi
+
diff --git a/salt/wazuh/init.sls b/salt/wazuh/init.sls
index 5825ed7d5..76d3fb1b4 100644
--- a/salt/wazuh/init.sls
+++ b/salt/wazuh/init.sls
@@ -62,6 +62,15 @@ wazuhagentregister:
- mode: 755
- template: jinja
+wazuhmgrwhitelist:
+ file.managed:
+ - name: /usr/sbin/wazuh-manager-whitelist
+ - source: salt://wazuh/files/wazuh-manager-whitelist
+ - user: 0
+ - group: 0
+ - mode: 755
+ - template: jinja
+
so-wazuhimage:
cmd.run:
- name: docker pull --disable-content-trust=false docker.io/soshybridhunter/so-wazuh:HH1.1.4
@@ -87,3 +96,9 @@ registertheagent:
- name: /usr/sbin/wazuh-register-agent
- cwd: /
#- stateful: True
+
+# Whitelist manager IP
+whitelistmanager:
+ cmd.run:
+ - name: /usr/sbin/wazuh-manager-whitelist
+ - cwd: /