Deploying Database Firewall for Monitoring
Learn about deploying Database Firewall on Oracle Cloud Infrastructure (OCI).
The following Database Firewall deployment modes are supported on OCI:
-
Monitoring / Blocking (Proxy)
-
Monitoring (Host Monitor)
Prerequisites:
-
For Database Firewall deployed in Monitoring (Host Monitor) mode, the virtual firewall for your Database Firewall VCN must be configured to allow ingress traffic on ports ranging from 2051 to 5100. See OCI Access and Security for complete information.
-
For Database Firewall deployed in Monitoring / Blocking (Proxy) mode, the virtual firewall for your Database Firewall VCN must be configured to open the specific proxy port.
-
For Audit Vault Server to collect network event data from Database Firewall, you must configure virtual firewall of your Database Firewall VCN to allow ingress traffic on port 1514.
When deploying Database Firewall, consider these points:
-
You can use either public or private IP address of the Database Firewall to register with the Audit Vault Server.
-
When configuring a Database Firewall monitoring point, use the primary VNIC as the network interface card.
-
Use private IP address of the target when enabling native network encrypted traffic monitoring for Oracle Database.
-
When configuring the Database Firewall monitoring point for Oracle Real Application Clusters (Oracle RAC), enter the FQDN of the SCAN Listener as the host name.
See Also:
Note:
-
Database Firewall monitoring and protection is not supported for targets outside OCI.
-
For deploying Host Monitor Agent follow the same guidelines mentioned in section Deploying Audit Vault Agents.