Get the App
SLTechnology News&Howtos  ›  Database  › 

RAC creates oracle whitelist

Shulou Source: shulou.com Published: 2022-06-01 07:56:00 10月04日 Update

Due to business needs, we need to use whitelist to limit the address of users logging in to the database, and decided to use the database whitelist function!

Generally, you only need to add the following to the sqlnet.ora to launch the whitelist of the instance database:

TCP.VALIDNODE_CHECKING=yes (enable IP restriction function)

TCP.INVITED_NODES= (192.168.1.103, ip2, ip3, and... Local IP..)-whitelist. Local IP is required, otherwise listening will not work.

TCP.EXCLUDED_NODES= (192.168.1.102)-blacklist

Because this environment is RAC, the operation is slightly different.

There is no sqlnet.ora file in the $ORACLE_HOME/NETWORK/ADMIN directory under the 1 ORACLE user. You must log in to the sqlnet.ora file under $ORACLE_HOME/NETWORK/ADMIN using the GUID user and add modifications.

2 Local IP must be added when adding whitelist. Because it is a RAC environment, real IP and private IP,VIP,SCAN IP with even sections must be added to the whitelist.

3 when starting up, you can't use lsnrctl reload like a stand-alone machine. You need to use srvctl stop listener-n node 1dje srvctl start listener-n node 1. You can modify one node and then modify another node to prevent business from being affected.

Tags: List node data database environment user business function file login restriction different content stand-alone address instance directory blacklist blackname influence Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno macOS MariaDB Shulou Technology OPPO Reno Linux