Allowlisting
Allowlisting is required to specify allowable access destinations on the public internet. There are networking scenarios documented in detail in Chapter 8: Network Integration Guidelines for Integrating Oracle Utilities Cloud Services with External Applications
IP Allowlisting
IP Allowlists enable customers to control how data flows into or out of their SaaS environments.
Inbound Traffic
Inbound traffic is controlled via allow list of IP addresses.
The inbound allow list feature provides a way to allow or deny inbound requests based on user-defined configuration.
By default, all inbound requests coming from all sources are allowed for Oracle Utilities Cloud Services.
Customers are given the capability to override this default behavior. It is possible to limit the sources that are able to perform inbound requests.
If a customer would like to customize or override the inbound allow list behavior, the expected flow is:
Customers need to determine how they will identify the sources that are allowed to access the resources:
via IP address ranges defined as CIDR blocks
via VCN OCID - only sources that access the resources via the OCI service gateway
both IP and VCN OCID
Outbound Traffic
Outbound traffic is controlled via allow list of IP addresses. Only HTTPS traffic is allowed to port 443.
The customer or system integrator can request a DNS (Domain name service) name to be added in the allowlist for outbound interface communication. An allowlist provides access to specified DNS addresses that the Oracle network would otherwise prevent access to. For Oracle Utilities cloud services, a customer or system integrator must request a DNS to be added to the allowlist for outbound communication to all external systems.
Once the requested DNS entry is added to the outbound allowlist, it is a customer responsibility to pro-actively maintain the following requirements:
TLS / SSL Certificate should be issued by a valid SSL Authority
Certificate's name(s) must match the server / endpoint name
Installation of TLS / SSL Certificate should include complete authentication chain
Expiry / Validation of TLS / SSL Certificate of the endpoint
Support minimum of TLS 1.2
Note: Customers may use TLS / SSL validations tools such as openssl, TLS / SSL verification websites (such as https://www.ssllabs.com/) to validate the compliance requirements mentioned above.
Configuring IP Allow Lists
To configure IP allow lists, customers must log a service request and follow the steps outlined in the following sections in Oracle Utilities Cloud Services Cloud Operations Guide to provide configuration details: