Go to main content

Oracle® Advanced Support Gateway Security Guide

Exit Print View

Updated: April 2024
 
 

Firewall Rules Between the Gateway and Oracle Database Appliance

This section provides a table showing the internal firewall rules between the Gateway and Oracle Database Appliance.

Table 12  Firewall Rules Between the Gateway and Oracle Database Appliance
Application Protocol
Source Interface(s)
Destination Interface(s)
Network Protocol/Port
Purpose
ICMP
All monitored interfaces
Gateway
ICMP Type 0 and 8
Used to test network connectivity between customer systems and the Gateway
ICMP
Gateway
All monitored interfaces
ICMP Type 0 and 8
Used to test network connectivity between the Gateway and customer systems
SNMP
Gateway
DB, Compute Node, and Compute Node ILOM
UDP/161
SNMP for ASR telemetry
ASR
Gateway
DB, Compute Node, and Compute Node ILOM
TCP/6481
ASR for discovery and monitoring by service tags
OEM
Gateway
DB, DomU, or Compute Node
HTTPS/1830-1839
OEM Agent communication, typically 1830 is used for Oracle Services
SSH/SCP
Gateway
DB, DomU, Compute Node, and Compute Node ILOM
TCP/22
Monitoring configuration, fault diagnostics, and patching
SNMP
DB, Compute Node, and Compute Node ILOM
Gateway
UDP/162
SNMP for monitoring events and/or network monitoring
HTTPS (OEM Agent)
DB, DomU, and Compute Node
Gateway
HTTPS/1159
OEM agent communication to the Gateway
RCMP+ (IPMI)
Gateway
Compute Node ILOM
UDP/623, TCP/623
Management and monitoring via ILOM interface (IPMI)
HTTPS
Gateway
DB or Compute Node ILOM
TCP/443
Monitoring configuration and fault diagnostic collection
HTTPS
DB
DomU
Compute Node
Gateway
TCP/443
Patch Download Service for patching support.
HTTP
DB
Compute Node
Compute Node ILOM
Gateway
HTTP/8234
ASR assets to communicate with ASR Manager