Go to main content

Oracle® Advanced Support Gateway Security Guide

Exit Print View

Updated: April 2024
 
 

Firewall Rules Between the Gateway and SuperCluster

This section provides a table showing the internal firewall rules between the Gateway and Oracle SuperCluster.

Table 10  Firewall Rules Between the Gateway and SuperCluster
Application Protocol
Source Interface(s)
Destination Interface(s)
Network Protocol/Port
Purpose
ICMP
All monitored interfaces
Gateway
ICMP Type 0 and 8
Used to test network connectivity between customer systems and the Gateway
ICMP
Gateway
All monitored interfaces
ICMP Type 0 and 8
Used to test network connectivity between the Gateway and customer systems
OEM
Gateway
All Domains
Zones based on monitoring service
HTTPS/1830-1839
OEM agent communication, typically 1830 is used for Oracle Services
SNMP
Gateway
InfiniBand
PDU
Cisco Switch
SPARC Server ILOMs (virtual/floating addresses as well as physical addresses)
Primary Domains
Cell Node
Cell Node ILOM
UDP/161
SNMP for ASR telemetry
ASR
Gateway
InfiniBand
SPARC Server ILOMs (virtual/floating addresses as well as physical addresses)
Primary Domains
Cell Node
Cell Node ILOM
TCP/6481
ASR for discovery and monitoring by service tags
HTTPS
Gateway
SPARC Server ILOMs (virtual/floating addresses as well as physical addresses)
InfiniBand
ZFS ILOM
Cell Node ILOM
TCP/443
Monitoring configuration and fault diagnostic collection
HTTPS
All Domains
Zones based on monitoring service
Gateway
TCP/443
Patch Download Service for patching support.
HTTPS - ZFS agent
Gateway
ZFS Controllers
TCP/215
OEM plug-in communication to ZFS for monitoring
SSH/SCP
Gateway
InfiniBand
ZFS Controllers
ZFS ILOM
SPARC Server ILOMs (Virtual/Floating addresses as well as Physical addresses)
Cell Node ILOM
Cell Node
PDU
All Domains
Zones based on monitoring service
Cisco Switch
TCP/22
Monitoring configuration, fault diagnostics, and patching
HTTP/HTTPS
Gateway
PDU
TCP/80 (HTTP)
Or
HTTPS/443
PDU web interface for monitoring configuration and diagnostics
SQL
Gateway
Database domains/zones
Client/VIP

Note -  if a database is only listening on a Client/VIP, access to this interface must also be allowed.

DB listener port, default is TCP/1521
DB listener port for discovery and ongoing monitoring

Note -  This is not required for Platinum Services customers.

RCMP+
Gateway
SPARC Server ILOMs (virtual/floating addresses as well as physical addresses)
Cell Node ILOM
ZFS ILOM
UDP/623, TCP/623
Management and monitoring using ILOM interface (IPMI)
WebLogic
Gateway
WebLogic instances
TCP/7001-7002
Monitoring install and diagnostics collection
HTTPS (OEM Agent)
All Domains
Zones based on monitoring service
Gateway
HTTPS/1159
OEM agent communication to the Gateway

Note -  For SuperCluster, customers must add static routes to force all traffic with the Gateway as its destination to use the Management Network as a primary interface for communication. The static route must be permanent because in the event of any restart of the nodes, the route will be deleted and communication between the agents and the Gateway will go down.

SNMP
Primary Domains
InfiniBand
PDU
Cisco Switch
SPARC Server ILOMs (virtual/floating addresses as well as physical addresses)
Cell Node
Cell Node ILOM
Gateway
UDP/162
SNMP for monitoring events
HTTP
Primary Domains
Gateway
TCP/5555
Solaris Explorer uploads for automatic uploads for events
HTTPS
Gateway
SuperCluster Control Domain
TCP/8000
Access to the IO Domain Creation Tool for monitoring and log file collection
ZFS Phone Home
ZFS Controllers
Gateway
TCP/8000
Gateway hosting a proxy server
HTTP
Primary Domains
SPARC Server ILOMs (virtual/floating addresses as well as physical addresses)
Cell Node
Cell Node ILOM
ZFS
ZFS ILOM
InfiniBand
Gateway
HTTP/8234
ASR assets to communicate with ASR Manager