Creating and Managing Profiles

Learn how to create and manage profiles in Database Firewall policy.

A profile is a named combination of one or more of the below sets:

  1. IP Address Set

  2. DB User Set

  3. OS User Set

  4. Client Program Set

You can create a user with the profile. For example, you can create a system DBA profile using the DB User Set. This set can contain all the DBA users.

To create a profile:

  1. Log in to the Oracle Database Security Central console as an auditor.

  2. Select Policies.

  3. Select Database Firewall Policies tab in the left navigation menu.

  4. Select the name of the specific policy.

  5. Select Sets/Profiles.

  6. Select Profiles sub This page lists the existing profiles. You can select a profile name to edit it.

    Note: Create a set first. It is not possible to create a profile without a set already existing.

  7. Select Add to create a new profile.

  8. In the Add profile dialog, enter the following:

    • Name: Enter a name for the profile.

    • Description: Optionally enter the description.

    • IP Address Set: From the list, select one of the available IP address sets, or leave it unselected.

    • DB User Set: From the list, select one of the available database user sets, or leave it unselected.

    • OS User Set: From the list, select one of the available operating system user sets, or leave it unselected.

    • Client Program Set: From the list, select one of the available client program sets, or leave it unselected.

      Note: Client program names and OS user names are provided by the client. Hence, they may not be reliable depending on the environment.

  9. Select Save.

    The profile appears in the Profiles sub You can now select this profile and set policy rules for the SQL Statements. The profile can be selected in a Database Object rule also.