Registering Database Firewall in Audit Vault Server
Use this procedure to register a Database Firewall with the Audit Vault Server.
Prerequisites
-
If you are deploying more than one Database Firewall, then you must register each firewall in Audit Vault Server to enable communication among the servers. We suggest that you first configure Database Firewall using the instructions in Configuring Database Firewall.
-
You must register Database Firewalls in Audit Vault Server before you can pair them for high availability. See Configuring High Availability for Database Firewalls for more information.
-
Provide the Audit Vault Server certificate and IP address to the Database Firewall that you are registering. See Specifying the Audit Vault Server Certificate and IP Address.
-
Run the following command on the Database Firewall to obtain the certificate fingerprint:
openssl x509 -in /usr/local/dbfw/etc/ca.crt -noout -fingerprint -sha256 -
Log in to Audit Vault Server as an administrator. See Using Oracle Database Security Central Console for more information.
To register Database Firewall in Audit Vault Server:
-
If there is a resilient pair of Audit Vault Servers, then log in to the primary server.
-
Select Database Firewalls.
The Firewalls page displays the currently registered firewalls and their statuses.
-
Select Register.
-
Enter a Name for Database Firewall, its IP Address, and Firewall Certificate SHA-256 Fingerprint.
-
Select Save.
Note:
-
If a message indicates that there is a problem with the certificate, then ensure that the date and time settings are identical on both Database Firewall and Audit Vault Server.
-
If the following error message is encountered, then check the Audit Vault Server certificate is copied properly to the Database Firewall. Also check the date and time settings are identical on both the Database Firewall and Audit Vault Server.
OAV-46981 Unable to connect to Database Firewall with IP -