Configuring Database Firewall Global Policy Settings
Learn how an auditor can configure or define an existing Database Firewall policy settings.
Global Policy settings in a Database Firewall represents the configuration settings applied to all the rules for a specific policy.
Prerequisite: Global Database Firewall settings can be configured after the policy is created.
-
Log in to the Oracle Database Security Central console as an auditor.
-
Select Policies.
-
From the left navigation menu, select Database Firewall Policies.
-
In this page, select the name of the specific policy.
-
Select Configuration. The following policy rules are displayed in different tabs:
-
Login / Logout
-
Sensitive Data Masking
-
Unknown Traffic
-
Policy Pattern
-
-
For example, select Policy Pattern In this configure the following:
-
Under Log Pattern section, select whether to Strip binary objects and comments from log files.
-
Under Action Rule Pattern section enter the Threshold action reset time (minutes) field. Enter a number in minutes. If you have set a Threshold in any of your policy rules, and the Threshold Action in your rule is taken, the action will not be repeated for the time you specify here. This prevents too many block/warn actions for the same rule.
-
In the Action without substitution field, select the action to take (No response or Drop connection) if one of your policy rules is set to Block and you have not specified a substitute statement in the rule.
-
Under the Syntax Rule Pattern section, select whether to treat Double quoted strings as identifiers. This determines whether double-quoted strings in SQL statements are treated as identifiers or string constants. If you deselect this checkbox, sensitive data masking (if used) will mask text in double quotes.
-
For Case sensitive match, select whether this firewall policy does case sensitive matching for Client program name, Database username, and Operating system username.
-
-
Select Save.