- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Blocking access to Oracle ports 1521/1526
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО06-06-2002 11:43 AM
тАО06-06-2002 11:43 AM
I'm trying to block access to our Oracle database from users on a certain subnet. The suggestion I got from HP Support was to make entries in hosts.allow/hosts.deny. I was under the impression that those files were part of the tcp_wrapper product. Is my assumption correct?
Also, since the Oracle listener is not an inetd controlled program, would tcp_wrapper do me any good?
Making entries in /var/adm/inetd.sec doesn't do any good because, again, the Oracle listener is not an inetd controlled program.
I'm trying to make some simple change at the network layer so we can still allow access to the Oracle db from other subnets.
Any ideas?
Thanks,
Tom
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО06-06-2002 11:51 AM
тАО06-06-2002 11:51 AM
SolutionI would recommend installing IPF/9000. It is product B9901AA on App CD 1.
The entry to block access to those ports in the ipf.conf file would be
block in quick proto tcp from any to IP/32 port = 1521
same with port 1526,
I have mine setup into groups which helps in filtering... but I digress
GL,
C
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО06-06-2002 11:54 AM
тАО06-06-2002 11:54 AM
Re: Blocking access to Oracle ports 1521/1526
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО06-07-2002 05:17 AM
тАО06-07-2002 05:17 AM
Re: Blocking access to Oracle ports 1521/1526
Thanks! It looks like that's just what I need. The only problem is, it appears that IPFilter is only available for 11.x. I'm migrating from 10.20 to 11.11 this weekend and I had hoped to be able to easily restrict access to the db on 10.20 while we did maintenance from our workstations preparing for the migration.
But it's not that big a problem. As Cristopher suggested, I'll have our WAN administrator do some blocking at the router and we ought to be fairly safe. And next week I'll be installing IPF/9000 on the 11.11 server.
Thanks again,
Tom
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО06-07-2002 05:20 AM
тАО06-07-2002 05:20 AM
Re: Blocking access to Oracle ports 1521/1526
Happy Migrating...
GL,
C
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО06-07-2002 06:14 AM
тАО06-07-2002 06:14 AM
Re: Blocking access to Oracle ports 1521/1526
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО06-07-2002 06:17 AM
тАО06-07-2002 06:17 AM
Re: Blocking access to Oracle ports 1521/1526
AR
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО06-07-2002 10:31 AM
тАО06-07-2002 10:31 AM
Re: Blocking access to Oracle ports 1521/1526
Thanks! It worked like a champ. I found a detailed document on using protocol.ora at metalink.oracle.com and just created a protocol.ora file with these entries:
tcp.validnode_checking = yes
tcp.invited_nodes = ( myhost )
Aashish,
Thanks. But since Stefan's simple method worked, I'll forgo implementing Connection Manager.
Tom