martes, 28 de mayo de 2019

How to Install Oracle Audit Vault Server 12c


Version of Oracle Audit Vault Server to install: 12.2.0.10.0 for Linux


Firstable you have to download the ISOs Files from edelivery.oracle.com


Insert the ISO for "Disk 1" and you will see the installation screen. Selects "Install (wipes system)":


The installation will start automatically:







The installation will request to insert the Disk 2:





The installation will continue:



The installation will request the Disk 3:



The installation will continue automatically:



The installation will request again the Disk 1:



The installation will continue automatically:




It will request you to enter the "Installation Passphrase". Don't loose this because it will be used at the end onf the installation. If you loose it you will have to reinstall the server from scratch.



Select The network interface you want to use:




Enter the IP for the Network:



The server will reboot:


The installation will continue automatically:








When the installation completes, the following menu will appear:



The Audit Vault Server web console will be available: https//192.168.56.40
(it's the IP we specified before for the Audit Vault Server)

In the very first login, the Installation Passphrase will be asked.



After to enter the Installation Passphrase, you have to specify the User and Password for the Administrator, auditor and some others OS accounts:




Now the console will disconnect your session and you will have to Login again, but this time using the users we already configured:



And now the Console can be accessed:



How to install Oracle Database Firewall 12c

Version of Oracle Database Firewall to install: 12.2.0.10.0

Insert the Oracle Database Firewall ISO disk into the machine:

Select "Install (wipes system)":



The Installation will start:








The installation will ask for the Installation Passphrase. Save this Passphrase because it will be used later, if you loose this you will have re-install from scratch.





Select The network interfaz to use for management:




Enter the IP for the selected Network Interface:



The server will reboot automatically:


The installation will continue automatically:



When the installation is completed you will see the following screen:



Then you will be able to access the Oracle Database Firewall web console using the Installation Passphrase:


In the first Login you will be asked to enter the users and passwords for the administrator user, and the OS users root and support.


Your session will be disconnected and you will have to connect again using the Administrator that was created before:


After that you will be able to access the Oracle Database Firewall web console:






How to configure Resilient Pair of Oracle Database Firewall in DAM mode

Version of Oracle Database Firewall used in this article: 12.2.0.10.0


Expected behaviour of Primary and Secondary Database Firewalls configured as a resilient pair

Resilient mode works in DAM mode only.
Both primary and secondary database firewalls:
  • Receive the same span traffic
  • Have the same configuration (the Management Server synchronizes this)
  • Create log files according to the policy applied
Only the primary database firewall:
  • Sends out real-time alerts
  • Runs user role and stored procedure audits
The Management server collects logs from the Primary database firewall, and deletes the log files from both database firewalls.

If the Primary database firewall is not available/cannot be contacted by the Management server, it collects the log files from the Secondary database firewall and promotes it to be Primary (so it will start sending out real-time alerts and running SPA/URA).



NOTE: The procedure described here applies to a Database Firewall in DAM mode only.


Prerequisites: 

You cannot have Enforcement Points already created in Oracle Audit Vault otherwise you will get the following error:




The IP of both Database Firewalls must be identical in the network configuration, otherwise you will receive the following error:



I recommend the following:
  • In both Database Firewall go to:
    • “System” -> “Network" And compare the following sections between both Oracle Database Firewall:
      • Management Interface
      • Traffic Sources
      • Traffic Proxies
      • Unallocated Network Interfaces
So for example, if you have a Traffic Sources configured in one Database Firewall, you should have also a Traffic Source in the other Database Fiewall.


Configuring Oracle Database Firewalls as Resilient Pair

Login in to Oracle Audit Vault
Click in “Database Firewall”
Click in “Resilient Pairs”
Click in “Create” Button




Select Primary and Secondary Database Firewalls





Click in "Create" Button





Click in "Save" Button


You will see that the Resilient Pair was added



If you go to “Database Firewalls” - > “Database Firewalls” you will see that the Secondary Database Firewall has a yellow color which means it’s the current “Standby Database Firewall”.

Oracle ACE Director Award - Deiby Gómez

Thanks #OracleACE Program for this awesome certificate recognizing the work I have done in the community for the last year. Looking forwa...