Managing Database Firewalls

Management tasks for Database Firewalls include tasks such as changing the network or services configuration.

Changing the Database Firewall Network or Services Configuration

Learn how to change the Database Firewall network or services configuration.

See one of the topics below if you need to change a Database Firewall’s network, traffic sources, or services configuration:

Viewing Network Traffic for a Database Firewall

You can capture and view network traffic in a .pcap file that you can download and analyze for debugging.

  1. Log in to the Oracle Database Security Central console as an administrator.

  2. Select Database Firewalls.

  3. In the left navigation menu, select Database Firewalls.

  4. Select link for the Database Firewall instance for which you want to capture network traffic.

  5. Under Diagnostics, select Network Traffic Capture.

  6. In the Network Traffic Capture dialog box, select the network traffic source in the Network Interface field.

  7. For Duration (min), set the number of minutes for which you want to capture traffic.

  8. Select Capture.

    After the specified duration, a message appears saying that the network files were successfully captured and the captured traffic file appears in the table.

    Note: The maximum file size of the captured network traffic is 1 MB. As soon as the file reaches that size, traffic capture stops, regardless of the specified duration. To capture traffic for longer durations, you can use a network protocol analyzer like Wireshark. For more details, see My Oracle Support Doc ID 2085200.1 and Doc ID 1141588.1.

  9. Select the network traffic file, and select Download.

  10. Specify the location and download the traffic file in .pcap format.

Restarting or Powering Off Database Firewall

Use this procedure to restart or power off Database Firewall.

To restart or power off a Database Firewall:

  1. Log in to the Audit Vault Server as an administrator.

  2. Select Database Firewalls.

  3. Select the specific Database Firewall you want to reboot or power off.

  4. Select Reboot or Power Off.

    See Also: Using Oracle Database Security Central Console

Removing Database Firewall from Audit Vault Server

You can remove Database Firewall from Audit Vault Server.

To remove Database Firewall from Audit Vault Server:

  1. Log in to the Audit Vault Server as an administrator.

  2. Select Database Firewalls.

  3. Select the specific Database Firewall you want to remove.

  4. Select Delete.

    See Also: Using Oracle Database Security Central Console

Fetching an Updated Certificate from Database Firewall

Learn how to obtain updated certificates from Database Firewall.

You can update the Database Firewall certificate stored in the Audit Vault Server using the Oracle Database Security Central console. You must update this certificate when you upgrade the Database Firewall to maintain communication between the Database Firewall and the Audit Vault Server.

To update the Database Firewall certificate stored in the Audit Vault Server:

  1. After upgrading the Database Firewall, log in to the Oracle Database Security Central console as an administrator.

  2. Select the Database Firewalls.

  3. In the left navigation menu, select Database Firewalls.

  4. Select the specific Database Firewall instance from the list.

  5. If the Database Firewall instance is down due to certificate validation error, then the Update Certificate button appears on the page. Select this button to update the certificate. For Database Firewall to accept the new certificate, you must provide the SHA-256 fingerprint when prompted.

See Also: Using Oracle Database Security Central Console

Viewing Diagnostics for Database Firewall

See Also: Viewing the Status and Diagnostics Report for Database Firewall for viewing Database Firewall diagnostics.

Resetting Database Firewall

Learn how to reset the Database Firewall instance.

This block contains information about the Database Firewall settings and the details of resetting a Database Firewall instance. Reset Firewall is available in the details page the specific Database Firewall instance. When you select Reset Firewall, you must enter the Database Firewall SHA-256 fingerprint to perform a reset of the Firewall ID. The Firewall ID is a unique identification number of the Database Firewall. It is derived from the Management Interface card.

Once the reset is performed, it removes the existing monitoring point instances and creates new ones using the configuration information stored in Audit Vault Server. The monitoring point instances not listed on the Audit Vault Server are removed once the reset is performed. The captured data which is not processed is also deleted. The network setting (Management Interface) of the Database Firewall is not altered. This operation restores the network interface card settings other than the Management Interface. It also restores the proxy ports information that was stored in the Audit Vault Server.

Note:

The user must reset the Firewall ID in the following scenarios:

  1. After replacing the Management Interface card on the Database Firewall.

  2. After replacing an existing and configured Database Firewall instance with a newly installed Database Firewall instance.

Restoring Database Firewall Monitoring Points

Learn how to restore Database Firewall monitoring points.

When you restore the Audit Vault Server from a backup, you must restore the status of the Database Firewall monitoring points that are registered with the Database Firewall.

See Also: Resetting Database Firewall for more information.