Configuring Database Firewall Monitoring Points

Learn about configuring Database Firewall monitoring points.

Note: If you are using Transparent Application Failover (TAF), Fast Application Notification (FAN), or the Oracle Notification Service (ONS), then SQL commands are not sent through this channel. There is no need to route them through Oracle Database Firewall. ONS communications bypass the Database Firewall and connect directly to the ONS listener. ONS communications, including destination host and port, are configured in the ons.config properties file located on the ONS server.

About Configuring Database Firewall Monitoring Points for Targets

Learn about configuring Database Firewall monitoring points for the target.

If you are monitoring databases with a Database Firewall, you must configure one monitoring point for every target database that you want to monitor with the firewall. The monitoring point configuration allows you to specify:

Oracle Database Firewall can be deployed in the following modes:

Before configuring monitoring points, configure network traffic sources as part of database firewall configuration.

See Also: Configuring the Database Firewall and Its Traffic Sources on Your Network

Creating and Configuring a Database Firewall Monitoring Point

Learn about creating and configuring Database Firewall monitoring points.

Configure Database Firewall monitoring points using the Oracle Database Security Central console. If you have configured a resilient pair of Audit Vault Servers, configure the monitoring points on the primary server.

Prerequisites

  1. Log in to the Oracle Database Security Central console as an administrator.

  2. Select Targets.

    The Targets in the left navigation menu is selected by default.

  3. Select the target that you want to modify.

  4. From the Database Firewall Monitoring section on the main page, select Add. The Database Firewall Monitor dialog is displayed.

  5. In the Core, select the Database Firewall instance from the list.

  6. Select a Mode from the following:

    • Monitoring (Out-of-Band)

    • Monitoring (Host Monitor)

    • Monitoring / Blocking (Proxy)

  7. In the Network Interface Card (NIC) field, select from the list of NICs. You may select a bonded NIC. Select from the list of NICs based on your monitoring mode:

    • Monitoring (Out-of-Band) - You may select multiple NICs from the list by holding the Control key on Windows or the Command key on Mac while selecting the NICs.

    • Monitoring / Blocking (Proxy) - You may select only one NIC from the list.

    • Monitoring (Host Monitor) - See Creating a Monitoring Point for the Host Monitor Agent

  8. Select the Proxy Ports from the list for Monitoring / Blocking (Proxy) mode. This field does not apply to other modes of Database Firewall deployment.

  9. In the Connection Details section, select one or more targets. You can Add the targets from the list.

    Note:

    • Select the RAC Instance/Autonomous DB checkbox if the target is Oracle Real Application Clusters. Select this option for Oracle Databases where the monitoring point is in Monitoring / Blocking (Proxy) mode. For Monitoring (Out-of-Band) mode, uncheck this box. Enter the IP address of the individual RAC node in Target Connections field.

    • Select the Network Interface Card and Proxy Ports for Monitoring / Blocking (Proxy) mode. The proxy port is not applicable for monitoring only modes.

    Enter the following information for each network location of the database. Select Add to configure the following additional details of the target instance:

    • Host Name / IP Address

      Note: For an Oracle RAC target, if the RAC Instance/Autonomous DB checkbox is selected, enter the FQDN of the SCAN Listener as the host name.

    • Port

    • Service Name (Optional, for Oracle Database only). SID can be used in this field. To enter multiple service names and/or SIDs, enter a new line for each of them, and then select Add. Multiple entries are allowed for monitoring only mode. For Monitoring / Blocking (Proxy) mode,

      • You can use one proxy port and specify multiple OSNs on the target database that are going to be processed. Specify the OSNs in a list delimited by the “" character. For example, target1\target2\target 3.

    Note: Targets are listed here with the policy details. Choose the right deployment mode as per the requirement. Choose Monitoring / Blocking (Proxy) for monitoring, blocking, and alerting. Choose Monitoring (Out-of-Band) or Monitoring (Host Monitor) modes for monitoring and alerting only.

  10. In the Advanced, enter the number of Database Firewall Monitor Threads (minimum and default value is 1). This controls the number of traffic handling threads in the Database Firewall monitoring point. Use due caution before modifying the value.

  11. If the target database is an Oracle Database and Mode is selected as Monitoring / Blocking (Proxy), the checkbox for Block Traffic for Unregistered Service Names is available for selection. When this checkbox is selected, Database Firewall blocks sessions that use service names other than the one that is configured in the target Connection Details section.

  12. If the database client and server are communicating over the TLS protocol, enable TLS.

    With this option, the Database Firewall acts as a TLS proxy. It serves as a TLS server for the database client and acts as a TLS client to the database server. The Database Firewall and the Audit Vault Server have access to the decrypted SQL traffic for further analysis. This feature applies only for Database Firewalls that are deployed in Monitoring / Blocking (Proxy) mode.

    1. Select Enable TLS support.

      Note: If you select this option, the Decrypt With Native Network Encryption Key checkbox is hidden.

    2. Select the certificate type under Inbound TLS (From client to DBFW).

      The TLS protocol uses the certificate to authenticate the communication participant. You can use the default certificate that is signed by the Database Firewall or a certificate that is signed by an external Certificate Authority (CA).

    3. If you use the default self-signed certificate, then select Download DBFW Certificate.

      You need to install this certificate on the database client to enable Database Firewall authentication.

    4. If you use the external CA signed certificate, then select the certificate from the drop-down list.

    5. Select the cipher suite level.

      Level 4 - strongest, is the default.

    6. If you don’t need database client authentication, then deselect Client Authentication.

      This option is available only for the inbound connection. The outbound connection is always authenticated. If you deselect this option, the Client Trusted Certificates button is disabled.

    7. To manage certificates for client authentication, select Client Trusted Certificates.

    8. Select Choose File and select the certificate on the local machine.

    9. Select Open to load the certificate and add it to the Database Firewall.

      The details of the uploaded certificate appear in the dialog box.

    10. Select Cancel to exit the dialog box.

    11. Follow a similar process to select and manage certificates and the cipher suite level under Outbound TLS (From DBFW to Database).

      To manage the certificates for server authentication, select Database Trusted Certificates.

  13. If Oracle Database uses native network encryption, select Decrypt With Native Network Encryption Key to enable the decryption of traffic.

    Note: If the Enable TLS support checkbox is selected, the Decrypt With Native Network Encryption Key checkbox is hidden.

    This option also supports the retrieval of session information for Oracle Database. Complete the remaining fields as applicable.

    For Oracle Real Application Clusters (Oracle RAC) targets (if the RAC Instance/Autonomous DB checkbox is selected on the Core), enter the SCAN Listener IP address.

    For Oracle standalone database targets, enter the IP address of the database listener.

    For Microsoft SQL databases, the field is Retrieve session information from target DB. Retrieving session information is not available for any other non-Oracle database types.

    Note: Ensure that the Database Firewall is allowed to make a network connection to the database listener.

  14. Select the Capture Database Response checkbox. If you select this checkbox, the Database Firewall monitors SQL responses from the database. Select the Full Error Message checkbox to capture database response and error codes.

  15. Select Save at the bottom of the dialog to save the configuration of the monitoring point.

    The new monitoring point appears in the list and starts automatically.

    Note: Default Database Firewall Policy will be applied for this Database Firewall Monitoring Point. This message is displayed at the bottom of the dialog.

  16. Select Save in the main page.

  17. To stop or restart the monitoring point, select it from the Database Firewall Monitoring section and select Stop or Start.

Note: When you use the Monitoring / Blocking (Proxy) mode, you must configure any external devices that use IP or MAC address spoofing detection rules such that they ignore database IP or MAC address changes made by the Database Firewall.

See Also:

Modifying a Database Firewall Monitoring Point

After you create a Database Firewall monitoring point, you can modify the settings, enable database response monitoring, monitor native network encrypted traffic for Oracle Database, and host monitoring.

  1. Log in to the Oracle Database Security Central console as an administrator.

  2. Select Targets.

    The Targets in the left navigation menu is selected by default.

  3. Select a specific target from the list.

  4. From the Database Firewall Monitoring section on the main page, select name of the monitoring point you want to modify.

  5. In the Database Firewall Monitor dialog, you can change some of the settings.

  6. Select a different Mode from the following:

    • Monitoring (Out-of-Band) - In this deployment mode, Database Firewall can monitor and alert on SQL traffic, but cannot block or substitute SQL statements.

    • Monitoring / Blocking (Proxy) - In this deployment mode, the Database Firewall can block or substitute SQL statements.

    • Monitoring (Host Monitor) - In this deployment mode, Database Firewall can monitor and alert on SQL traffic, but cannot block or substitute SQL statements.

      Note:

      • While configuring the Monitoring (Host Monitor) deployment mode, you must select a NIC which has an IP address configured. This may be the Management Interface. This is the NIC to which the Host Monitor Agent will connect. When you select Monitoring (Host Monitor) as the deployment type, only those network interface cards which have IP address configured are displayed in the Network Interface Card field.
  7. Select a different traffic source in the field Network Interface Card.

  8. In the Advanced, enter the number of Database Firewall Monitor Threads (minimum value is 1). This controls the number of traffic handling threads in the Database Firewall monitoring point. This value should be left at the default (1) unless there are indications that the Database Firewall is unable to cope with the amount of traffic it is receiving.

  9. If the target database is an Oracle Database and Mode is selected as Monitoring / Blocking (Proxy), the checkbox for Block Traffic for Unregistered Service Names is available for selection. When this checkbox is selected, Database Firewall blocks sessions that use service names other than the one that is configured in the target Connection Details section.

  10. If the database client and server are communicating over the TLS protocol, enable TLS.

    With this option, the Database Firewall acts as a TLS proxy. It serves as a TLS server for the database client and acts as a TLS client to the database server. The Database Firewall and the Audit Vault Server have access to the decrypted SQL traffic for further analysis. This feature applies only for Database Firewalls that are deployed in Monitoring / Blocking (Proxy) mode.

    1. Select Enable TLS support.

      Note: If you select this option, the Decrypt With Native Network Encryption Key checkbox is hidden.

    2. Select the certificate type under Inbound TLS (From client to DBFW).

      The TLS protocol uses the certificate to authenticate the communication participant. You can use the default certificate that is signed by the Database Firewall or a certificate that is signed by an external Certificate Authority (CA).

    3. If you use the default self-signed certificate, then select Download DBFW Certificate.

      You need to install this certificate on the database client to enable Database Firewall authentication.

    4. If you use the external CA signed certificate, then select the certificate from the drop-down list.

    5. Select the cipher suite level.

      Level 4 - strongest, is the default.

    6. If you don’t need database client authentication, then deselect Client Authentication.

      This option is available only for the inbound connection. The outbound connection is always authenticated. If you deselect this option, the Client Trusted Certificates button is disabled.

    7. To manage certificates for client authentication, select Client Trusted Certificates.

    8. Select Choose File and select the certificate on the local machine.

    9. Select Open to load the certificate and add it to the Database Firewall.

      The details of the uploaded certificate appear in the dialog box.

    10. Select Cancel to exit the dialog box.

    11. Follow a similar process to select and manage certificates and the cipher suite level under Outbound TLS (From DBFW to Database).

      To manage the certificates for server authentication, select Database Trusted Certificates.

  11. If Oracle Database uses native network encryption, select Decrypt With Native Network Encryption Key to enable the decryption of traffic.

    Note: If the Enable TLS support checkbox is selected, the Decrypt With Native Network Encryption Key checkbox is hidden.

    This option also supports the retrieval of session information for Oracle Database. Complete the remaining fields as applicable.

    For Oracle Real Application Clusters (Oracle RAC) targets (if the RAC Instance/Autonomous DB checkbox is selected on the Core), enter the SCAN Listener IP address.

    For Oracle standalone database targets, enter the IP address of the database listener.

    For Microsoft SQL databases, the field is Retrieve session information from target DB. Retrieving session information is not available for any other non-Oracle database types.

    Note: Ensure that the Database Firewall is allowed to make a network connection to the database listener.

  12. Select the Capture Database Response checkbox. If you select this checkbox, the Database Firewall monitors SQL responses from the database. Select the Full Error Message checkbox to capture database error codes and messages.

  13. Select Save at the bottom of the dialog to save the configuration of the monitoring point.

  14. Select Save in the main page.

Starting, Stopping, or Deleting Database Firewall Monitoring Points

Learn about starting, stopping, and deleting Database Firewall monitoring points.

  1. Log in to the Oracle Database Security Central console as an administrator.

  2. Select Targets.

  3. Select a specific target. The details of the target are displayed on the main page.

  4. Under Database Firewall Monitoring, select a specific Database Firewall monitoring point.

  5. Select one of the following buttons:

    • Start - To start the monitoring point

    • Stop - To stop the monitoring point

    • Delete - To delete the monitoring point

    See Also: Using Oracle Database Security Central Console

Viewing the Status of Database Firewall Monitoring Points

Learn about viewing Database Firewall monitoring point status.

  1. Log in to the Oracle Database Security Central console as an administrator.

  2. Select Targets.

  3. Select a specific target. The details of the specific target are displayed on the main page.

  4. Under the Database Firewall Monitoring section, view the list of Database Firewall monitoring points.

    A list of monitoring points and their status is displayed. Possible status values are:

    • Up - The monitoring point is up and running, and there are no errors.

    • Suspended - The user has stopped the monitoring point, and there are no errors.

    • Down - The monitoring point is not working, probably due to errors.

    • Unreachable - There are communication errors between the Database Firewall and the Audit Vault Server.

    See Also: Using Oracle Database Security Central Console

Finding the Port Number Used by a Database Firewall Monitoring Point

Learn about finding Database Firewall monitoring point port numbers.

  1. Log in to the Oracle Database Security Central console as an administrator.

  2. Select Targets.

  3. Select a specific target. The details of the specific target are displayed on the main page.

  4. Under Database Firewall Monitoring section, select a specific Database Firewall monitoring point.

  5. The port number is displayed in the field Proxy Ports.

    See Also: Using Oracle Database Security Central Console

Configuring a Database Firewall to Connect to an Oracle Autonomous AI Database

Learn how to configure a Database Firewall to connect to an Oracle Autonomous AI Database.

Prerequisite: Log in to the Oracle Cloud Infrastructure (OCI) account and download the wallet credentials ZIP file that is associated with the user account.

  1. Create a TLS-enabled Database Firewall monitoring point for the Oracle Autonomous AI Database target.

    • On the Core, select RAC Instance/Autonomous DB.

    • On the Advanced, select Enable TLS support.

    For complete instructions, see Creating and Configuring a Database Firewall Monitoring Point.

  2. Complete the TLS configuration for inbound connections.

    See Modifying a Database Firewall Monitoring Point.

  3. Import the wallet ZIP file that is associated with the user account (which you downloaded earlier) to the Database Firewall instance.

    1. Copy the wallet ZIP file to the file system on the Database Firewall (for example, /tmp/Wallet_DBXXXXXXXXXX.zip).

    2. Log in to the Database Firewall through SSH and switch to the root user.

    3. Extract the contents of the wallet ZIP file.

      unzip /tmp/Wallet_DBXXXXXXXXXX.zip -d my_cloud_wallet
    4. Run the following command to deploy the wallet for the appropriate Database Firewall secured target:

      /opt/avdf/bin/deploy-wallet  <PATH-TO-UNZIPPED-CLOUD-WALLET>  <SECURED-TARGET-NAME>

      Note:

      To view the list of all available secured targets, run the following command:

      /opt/avdf/bin/deploy-wallet --list-targets