Go to main content

Oracle® Advanced Support Gateway Security Guide

Exit Print View

Updated: April 2024
 
 

Firewall Rules Between the Gateway and ZDLRA

This section provides a table showing the internal firewall rules between the Gateway and Oracle Zero Data Loss Recovery Appliance (ZDLRA).

Table 7  Firewall Rules Between the Gateway and Zero Data Loss Recovery Appliance
Application Protocol
Source Interface(s)
Destination Interface(s)
Network Protocol/Port
Purpose
ICMP
All monitored interfaces
Gateway
ICMP Type 0 and 8
Used to test network connectivity between customer systems and the Gateway
ICMP
Gateway
All monitored interfaces
ICMP Type 0 and 8
Used to test network connectivity between the Gateway and customer systems
OEM
Gateway
Compute Node
HTTPS/1830-1839
OEM Agent communication; typically port 1830 is used for Oracle Services
SNMP
Gateway
InfiniBand
PDU
Cisco Switch
Storage Node ILOM
Storage Node
Compute Node ILOM
Compute Node
UDP/161
SNMP for ASR telemetry
SNMP
Compute Node and DomU
PDU
Cisco Switch
UDP/161
Monitoring of hardware components
ASR
Gateway
InfiniBand
Storage Node
Storage Node ILOM
Compute Node
Compute Node ILOM
TCP/6481
ASR for discovery and monitoring by service tags
HTTPS
Gateway
Storage Node ILOM
Compute Node ILOM
InfiniBand
HTTPS/443
Monitoring configuration and fault diagnostic collection
HTTPS
Compute Node
Gateway
TCP/443
  • The Patch Download Service for patching support

  • Autonomous Health Framework (AHF) integration

  • OASG Agent communication

HTTP/HTTPS
Gateway
PDU

Note -  In late Exadata X4-2 and X5-2 or above, the PDU Web interface can only be accessed using HTTPS (not HTTP.)

TCP/80 (HTTP)
Or
TCP/443 (HTTPS)
PDU web interface for monitoring configuration and diagnostics
SSH/SCP
Gateway
InfiniBand
Storage Node
Storage Node ILOM
Compute Node
Compute Node ILOM
PDU
TCP/22
Monitoring configuration, fault diagnostics, and patching
SSH/SCP
Gateway
Cisco Switch
TCP/22 (SSH/SCP)
Monitoring configuration, fault diagnostics, and patching
SQL
Gateway
DB listener IP (VIP)

Note -  If a database is only listening on a Client/VIP, then access to this interface must also be allowed.

DB listener port, default is TCP/1521
DB listener port for discovery and ongoing monitoring
RCMP+
Gateway
Storage Node ILOM
Compute Node ILOM
UDP/623, TCP/623
Management and monitoring via ILOM interface (IPMI)
HTTPS (OEM Agent)
Compute Node
Gateway
HTTPS/1159
OEM agent communication to the Gateway

Note -  For Zero Data Loss Recovery Appliance, customers must add static routes to force all traffic with the Gateway as its destination to use the Management Network as a primary interface for communication. The static route must be permanent because in the event of any restart of the nodes, the route will be deleted and communication between the agents and the Gateway will go down.

SNMP
InfiniBand
PDU
Cisco Switch
Storage Node ILOM
Storage Node
Compute Node ILOM
Compute Node
Gateway
UDP/162
SNMP for monitoring events and/or network monitoring
HTTP
Storage Node ILOM
Storage Node
Compute Node ILOM
Compute Node
Cisco Switch
Inifiniband
Gateway
HTTP/8234
ASR assets to communicate with ASR Manager