Importing Database Firewall Policies

Learn how to import one or more Database Firewall policies.

  1. Log in to the Oracle Database Security Central console as an auditor.

  2. Select Policies.

  3. Select Database Firewall Policies tab in the left navigation menu.

  4. Select Import.

  5. In the Import Policy dialog, select and navigate to choose the encrypted JSON file that contains all the details of the Database Firewall policies.

  6. Enter the Password. It is the same password that was set when the Database Firewall policies were exported earlier.

  7. Select an Action for conflicting policy. This will determine how imported policies and sets will interact with existing global user, sensitive object, and global sets from Global Sets/Data Discovery. Options include:

    • Create new policy ensuring the global set names are unique: Creates a new policy and any global imported set names will be unique.

    • Create new policy and keep all sets local: Creates a new policy and all imported sets will be local to this new policy.

    • Replace the existing policy and the policy sets: Replace any existing policies and sets with the same name with those that are being imported.

    Sets of database users and database objects can be global or local sets. Global sets can be viewed in and applied to multiple database firewall policies, whereas local sets can only be viewed in and applied to the database firewall policies they were created in. Global sets can be created inDiscover & Classify.

  8. Select Save.

    A confirmation message of the import process is displayed. The User-defined Database Firewall policies are imported. The policy details are copied to the Audit Vault Server instance and the policies are published. In case there is a name conflict with any of the policies, then a sequence number is added to differentiate. The Audit Vault Server also checks for the file format, validates the JSON file, fields, and values. In case of any issues, an error message is displayed.

    The import process is a background job. The status of the job is displayed in the Jobs dialog. The name of the job is DBFW Policy Import.

  9. The newly imported policy appears in the list. The Imported column specifies whether the policy was imported or not. Make any changes to the policy and save them accordingly. The imported policies are published by default, and can be deployed to the Database Firewall. In case there are any further changes required, they can be published again after modification.

Note: In case the Database Firewall policy has SQL cluster sets and the pertaining SQL statements are not already captured in the Audit Vault Server, then the SQL traffic details are not displayed when the auditor drills down in the cluster for troubleshooting.