Creating and Managing Profiles
Learn how to create and manage profiles in Database Firewall policy.
A profile is a named combination of one or more of the below sets:
-
IP Address Set
-
DB User Set
-
OS User Set
-
Client Program Set
You can create a user with the profile. For example, you can create a system DBA profile using the DB User Set. This set can contain all the DBA users.
To create a profile:
-
Log in to the Oracle Database Security Central console as an auditor.
-
Select Policies.
-
Select Database Firewall Policies tab in the left navigation menu.
-
Select the name of the specific policy.
-
Select Sets/Profiles.
-
Select Profiles sub This page lists the existing profiles. You can select a profile name to edit it.
Note: Create a set first. It is not possible to create a profile without a set already existing.
-
Select Add to create a new profile.
-
In the Add profile dialog, enter the following:
-
Name: Enter a name for the profile.
-
Description: Optionally enter the description.
-
IP Address Set: From the list, select one of the available IP address sets, or leave it unselected.
-
DB User Set: From the list, select one of the available database user sets, or leave it unselected.
-
OS User Set: From the list, select one of the available operating system user sets, or leave it unselected.
-
Client Program Set: From the list, select one of the available client program sets, or leave it unselected.
Note: Client program names and OS user names are provided by the client. Hence, they may not be reliable depending on the environment.
-
-
Select Save.
The profile appears in the Profiles sub You can now select this profile and set policy rules for the SQL Statements. The profile can be selected in a Database Object rule also.