Go to main content

Oracle® Advanced Support Gateway Security Guide

Exit Print View

Updated: April 2024
 
 

Firewall Rules Between the Gateway and Exalogic

This section provides a table showing the internal firewall rules between the Gateway and Oracle Exalogic Elastic Cloud.

Table 9  Firewall Rules Between the Gateway and Exalogic
Application Protocol
Source Interface(s)
Destination Interface(s)
Network Protocol/Port
Purpose
ICMP
All monitored interfaces
Gateway
ICMP Type 0 and 8
Used to test network connectivity between customer systems and the Gateway
ICMP
Gateway
All monitored interfaces
ICMP Type 0 and 8
Used to test network connectivity between the Gateway and customer systems
OEM
Gateway
Compute Node
Control VMs (virtual only)
HTTPS/1830-1839
OEM Agent communication, typically 1830 is used for Oracle Services
SNMP
Gateway
InfiniBand
PDU
Cisco Switch
Compute Node
Compute Node ILOM
Virtual Instances
ZFS ILOM
ZFS Controllers
UDP/161
SNMP for ASR telemetry
ASR
Gateway
Compute Node
Compute Node ILOM
InfiniBand
TCP/6481
ASR for discovery and monitoring by service tags
HTTPS
Gateway
Compute Node ILOM
InfiniBand
ZFS ILOM
TCP/443
Monitoring configuration and fault diagnostic collection
HTTPS
Compute Node
OVS Compute Node
Control VMs
Gateway
TCP/443
Patch Download Service for patching support.
HTTP/HTTPS
Gateway
PDU

Note -  In late Exalogic X4-2 and X5-2 or above, the PDU Web interface can only be accessed using HTTPS (not HTTP.)

TCP/80 (HTTP)
Or
HTTPS/443
PDU web interface for monitoring configuration and diagnostics
SSH/SCP
Gateway
InfiniBand
Control VMs (virtual only)
ZFS Controllers
Compute Node
ZFS ILOM
Compute Node ILOM
PDU
Cisco Switch
TCP/22
Monitoring configuration, fault diagnostics, and patching
SQL
Gateway
Control VMs (Virtual only)

Note -  If a database is only listening on a Client/VIP access to this interface must also be allowed.

DB listener port, default is TCP/1521
DB listener port for discovery and ongoing monitoring
RCMP+
Gateway
Compute Node ILOM
ZFS ILOM
UDP/623, TCP/623
Management and monitoring using the ILOM interface (IPMI)
HTTPS
Gateway
Compute Node
TCP/7001-7002
Monitoring install and diagnostics collection
HTTPS - ZFS agent
Gateway
ZFS Controllers
TCP/215
OEM plug-in communication to ZFS for monitoring
HTTPS (OEM agent)
Compute Node
Control VMs (virtual only)
Gateway
HTTPS/1159
OEM agent communication to the Gateway

Note -  For Exalogic, customers must add static routes to force all traffic with the Gateway as its destination to use the Management Network as a primary interface for communication. The static route must be permanent because in the event of any restart of the nodes, the route will be deleted and communication between the agents and the Gateway will go down.

SNMP
InfiniBand
PDU
Cisco Switch
Compute Node
Compute Node ILOM
Gateway
UDP/162
SNMP for Monitoring Events
HTTP
Compute Node (Solaris)
Zones
Gateway
TCP/5555
Solaris Explorer uploads for automatic uploads for events
ZFS Phone Home
ZFS Controllers
Gateway
TCP/8000
Gateway hosting a proxy server
HTTP
Compute Node
Compute Node ILOM
ZFS Controllers
ZFS ILOM
InfiniBand
Gateway
HTTP/8234
ASR Assets to communicate with ASR Manager