專用端點先決條件

若要使用專用端點佈建 Oracle Fusion Data Intelligence 執行處理,您必須已經建立下列資源:

  1. 您計畫在其中部署 Oracle Fusion Data Intelligence 的區域內的虛擬雲端網路 (VCN),以及 VCN 中的專用子網路 (可用性為 /28 (14 個 IP 位址) 以上的 IP 位址。您可以在啟動設定之後變更此設定。
    為避免建立執行處理失敗,請確定啟用下列選項:

    Oracle Fusion Data Intelligence 需要這些選項,才能順利佈建執行處理及其元件。請參閱使用 VCN 和子網路

    備註:

    當您自訂 DNS 解析器時,請務必以最高優先順序新增 Oracle Autonomous AI Database DNS 解析器。
  2. 設定安全性規則。您必須為傳入和傳出設定狀態性規則。請參閱狀態性與無狀態規則的比較
    設定安全規則時,請確定下列項目:
    • 來源 CIDR :必須是 0.0.0.0/0<VCN CIDR><SUBNET CIDR>
    • IP 協定TCPAll Protocols
    • 來源港口範圍ALL
    • 目的地連接埠範圍ALL,或特別是 1522443

    備註:

    Oracle Autonomous AI Lakehouse 指定連接埠 1522 的輸入和輸出流量,為 Oracle Analytics Cloud 指定連接埠 443,同時輸入網路安全群組或 VCN 的安全規則資訊。確定 VCN/SUBNET CIDR 區塊允許將規則中的傳入和傳出至連接埠 443 和 1522。使用專用端點的 Oracle Fusion Data Intelligence 執行處理必須同時使用這兩個連接埠。


    fawag-ingress-rules-pvt-fdi-oak.png 的描述如下
    fawag-ingress-rules-pvt-fdi-oak.png 圖解描述


    fawag-egress-rules-pvt-fdi.png 的描述如下
    fawag-egress-rules-pvt-fdi.png 圖解描述

  3. 如果您計畫使用網路安全群組規則限制流量 (傳入和傳出),則必須在建立 Oracle Fusion Data Intelligence 執行處理時這麼做。您最多可以指定 5 個網路安全性群組,以符合您的業務需求。請確定網路安全群組與您的 Oracle Fusion Data Intelligence 位於相同的 VCN 中。
  4. 確保您 (或任何計劃建立 Oracle Fusion Data Intelligence 執行處理的人員) 具備存取 VCN 的必要原則。

    從下列選項中選擇最適合您的層次:

    限制的資源存取原則

    • Allow any-user to manage network-security-groups in tenancy where request.principal.type = 'fawservice'
    • Allow any-user to use vnics in tenancy where request.principal.type = 'fawservice'
    • Allow any-user to read vcns in tenancy where request.principal.type = 'fawservice'
    • Allow any-user to use private-ips in tenancy where request.principal.type = 'fawservice'
    • Allow any-user to use subnets in tenancy where request.principal.type = 'fawservice'

    如果您想要從 Oracle Cloud Infrastructure 主控台檢視及管理您的虛擬網路系列,您可以建立下列原則:

    • Allow group FAWAdmin.grp to manage network-security-groups <in compartment your-compartment or in tenancy>
    • Allow group FAWAdmin.grp to read virtual-network-family <in compartment your-compartment or in tenancy>
    • Allow group FAWAdmin.grp to manage vnics <in compartment your-compartment or in tenancy>
    • Allow group FAWAdmin.grp to use subnets <in compartment your-compartment or in tenancy>
    • Allow group FAWAdmin.grp to use private-ips <in compartment your-compartment or in tenancy>

    廣泛的資源存取原則

    Allow any-user to manage virtual-network-family in tenancy where
          request.principal.type = 'fawservice'
    若要從 Oracle Cloud Infrastructure 主控台檢視及管理您的虛擬網路系列,請建立此原則:
    Allow group FAWAdmin.grp to manage virtual-network-family <in compartment compartment-name or in tenancy>

    除此之外,您必須建立下列一般服務原則:

    • Allow group FAWAdmin.grp to manage analytics-warehouse <in compartment your-compartment or in tenancy>
    • Allow group FAWAdmin.grp to read analytics-warehouse-work-requests <in compartment your-compartment or in tenancy>
    • Allow group FAWAdmin.grp to manage autonomous-database-family <in compartment your-compartment or in tenancy>
    • Allow group FAWAdmin.grp to manage analytics-instances <in compartment your-compartment or in tenancy>
    • Allow group FAWAdmin.grp to read analytics-instance-work-requests <in compartment your-compartment or in tenancy>