Go to main content

Oracle® Advanced Support Gateway Security Guide

Exit Print View

Updated: June 2024
 
 

Firewall Rules Between the Gateway and Exadata

This section provides a table showing the internal firewall rules between the Gateway and Oracle Exadata Database Machine.

Table 6  Firewall Rules Between the Gateway and Exadata
Application Protocol
Source Interface(s)
Destination Interface(s)
Network Protocol/Port
Purpose
ICMP
All monitored interfaces
Gateway
ICMP Type 0 and 8
Used to test network connectivity between customer systems and the Gateway
ICMP
Gateway
All monitored interfaces
ICMP Type 0 and 8
Used to test network connectivity between the Gateway and customer systems
ICMP
DB Node and DomU
InfiniBand
Cell Node
Cell Node ILOM
DB Node
DB Node ILOM
PDU
Cisco Switch
ICMP Type 0 and 8
Monitoring of hardware components
OEM
Gateway
DB Node and DomU
HTTPS/1830-1839
OEM Agent communication; typically port 1830 is used for Oracle Services
SNMP
Gateway
InfiniBand
PDU
Cisco Switch
Cell Node ILOM
Cell Node
DB Node ILOM
DB Node and DomU
UDP/161
SNMP for ASR telemetry
ASR
Gateway
InfiniBand
Cell Node
Cell Node ILOM
DB Node
DB Node ILOM
TCP/6481
ASR for discovery and monitoring by service tags
HTTPS
Gateway
Cell Node ILOM
DB Node ILOM
InfiniBand
HTTPS/443
Monitoring configuration and fault diagnostic collection
HTTPS
DB Node and DomU
Gateway
HTTPS/443
  • The Patch Download Service for patching support

  • Autonomous Health Framework (AHF) Integration

  • OASG Agent communication

HTTP/HTTPS
Gateway
PDU

Note -  In late Exadata X4-2 and X5-2 or above, the PDU Web interface can only be accessed using HTTPS (not HTTP.)

TCP/80 (HTTP)
Or
HTTPS/443
PDU web interface for monitoring configuration and diagnostics
SSH/SCP
Gateway
InfiniBand
Cell Node
Cell Node ILOM
DB Node and DomU
DB Node ILOM
PDU
TCP/22
Monitoring configuration, fault diagnostics, and patching
SSH/SCP
DB Node and DomU
InfiniBand
Cell Node
Cell Node ILOM
DB Node
DB Node ILOM
PDU
Cisco Switch
TCP/22
Monitoring of hardware components
SNMP
DB Node and DomU
PDU
Cisco Switch
UDP/161
Monitoring of hardware components
SSH/SCP
Gateway
Cisco Switch
TCP/22 (SSH/SCP)
Monitoring configuration, fault diagnostics, and patching
SQL
Gateway
DB listener IP (VIP)

Note -  If a database is only listening on a Client/VIP, then access to this interface must also be allowed.

DB listener port, default is TCP/1521
DB listener port for discovery and ongoing monitoring

Note -  This is not required for Platinum Services customers.

RCMP+
Gateway
Cell Node ILOM
DB Node ILOM
UDP/623, TCP/623
Management and monitoring via ILOM interface (IPMI)
HTTPS (OEM Agent)
DB Node and DomU
Gateway
HTTPS/1159
OEM agent communication to the Gateway

Note -  For Exadata, customers must add static routes to force all traffic with the Gateway as its destination to use the Management Network as a primary interface for communication. The static route must be permanent because in the event of any restart of the nodes, the route will be deleted and communication between the agents and the Gateway will go down.

SNMP
InfiniBand
PDU
Cisco Switch
Cell Node ILOM
Cell Node
DB Node ILOM
DB Node
Gateway
UDP/162
SNMP for monitoring events and/or network monitoring
HTTP
Cell Node ILOM
Cell Node
DB Node ILOM
DB Node
Cisco switch
InfiniBand
Gateway
HTTP/8234
ASR assets to communicate with ASR Manager