Go to main content

Oracle® Advanced Support Gateway for Cloud at Customer Security Guide

Exit Print View

Updated: August 2020
 
 

Firewall Rules Between the Gateway and Fusion Applications (SaaS at Customer)

This section provides a table showing the internal firewall rules between Oracle Advanced Support Gateway and Oracle Fusion Applications (SaaS at Customer.)

Table 5  Firewall Rules Between the Gateway and Fusion Applications (SaaS at Customer)
Application Protocol
Source Interface(s)
Destination Interface(s)
Network & Network Protocol/Port
Purpose
ICMP
Oracle Advance Support Gateway
Fusion Application DomU/VMs
Tenant network
ICMP/Echo, Reply
Used to test network connectivity between Oracle Cloud Machine systems and Oracle Advance Support Gateway
SSH
Oracle Advance Support Gateway
Fusion Application DomU/VMs
Tenant network
TCP/22
Supports user access to monitor configuration, review diagnostics (logs, thread dumps, JFR heap dump), operations/support and patching of Fusion Applications DomU's/VM's
HTTPS
Fusion Application DomU/VMs
Oracle Advance Support Gateway
Tenant network
TCP/1159
Agent communication, upload monitoring, lifecycle management (LCM), decoupled target discovery process
HTTPS
Oracle Advance Support Gateway
Fusion Application DomU/VMs
Tenant network
TCP/1830
OEM agent communication for Fusion Applications monitoring and support
HTTPS
Oracle Advance Support Gateway
Fusion Application DomU/VMs
Tenant network
TCP/ 7001, 7401, 7801, 8201, 8601, 9001, 9401, 9801, 10201, 11201, 17001, 10600-10625, 11401, 10663
Oracle WebLogic Server administration and operational support for Fusion Applications
Connectivity is over HTTPS and exclusively connects to administration ports of Fusion Applications domains
SQLNet
Oracle Advance Support Gateway
Fusion Application DB hosts/Oracle Database Exadata Cloud at Customer (ExaCC)
Tenant network
TCP/1521-1530
Target database discovery from Oracle Enterprise Manager for monitoring and ongoing support of the database