martes, 28 de mayo de 2019

How to configure Resilient Pair of Oracle Database Firewall in DAM mode

Version of Oracle Database Firewall used in this article: 12.2.0.10.0


Expected behaviour of Primary and Secondary Database Firewalls configured as a resilient pair

Resilient mode works in DAM mode only.
Both primary and secondary database firewalls:
  • Receive the same span traffic
  • Have the same configuration (the Management Server synchronizes this)
  • Create log files according to the policy applied
Only the primary database firewall:
  • Sends out real-time alerts
  • Runs user role and stored procedure audits
The Management server collects logs from the Primary database firewall, and deletes the log files from both database firewalls.

If the Primary database firewall is not available/cannot be contacted by the Management server, it collects the log files from the Secondary database firewall and promotes it to be Primary (so it will start sending out real-time alerts and running SPA/URA).



NOTE: The procedure described here applies to a Database Firewall in DAM mode only.


Prerequisites: 

You cannot have Enforcement Points already created in Oracle Audit Vault otherwise you will get the following error:




The IP of both Database Firewalls must be identical in the network configuration, otherwise you will receive the following error:



I recommend the following:
  • In both Database Firewall go to:
    • “System” -> “Network" And compare the following sections between both Oracle Database Firewall:
      • Management Interface
      • Traffic Sources
      • Traffic Proxies
      • Unallocated Network Interfaces
So for example, if you have a Traffic Sources configured in one Database Firewall, you should have also a Traffic Source in the other Database Fiewall.


Configuring Oracle Database Firewalls as Resilient Pair

Login in to Oracle Audit Vault
Click in “Database Firewall”
Click in “Resilient Pairs”
Click in “Create” Button




Select Primary and Secondary Database Firewalls





Click in "Create" Button





Click in "Save" Button


You will see that the Resilient Pair was added



If you go to “Database Firewalls” - > “Database Firewalls” you will see that the Secondary Database Firewall has a yellow color which means it’s the current “Standby Database Firewall”.

No hay comentarios:

Publicar un comentario

Oracle ACE Director Award - Deiby Gómez

Thanks #OracleACE Program for this awesome certificate recognizing the work I have done in the community for the last year. Looking forwa...