blocking direct access to the oracle server

Dear Sir

One of our condition of pci - dss to stop direct access to the db. One solution I know:

TCP.validnode_checking = YES

TCP.invited_nodes = (192.168.1.91, visionhost.solutionbeacon.com)

But this option will allow the IP address of the node invited with sqlplus using tns names also. Have any have experience to solve the problem of ending up with pci - dss?

In which paragraph of the PCI - DSS doc that makes you think that there is a problem? I work with version 3.0 (November 2013) and I can't find anything like that. For example, paragraph 8.7 c, "review of database access control settings and application of database to verify configuration settings that the user access directly to the or queries of databases are limited to database administrators" does not say that the DBA is not able to connect to the application server. And all the stuff of firewall in requirement 1 close the access to the network and between networks, not within the network.

Are you sure that you have a problem? There is no interest to 'fix' something that doesn't have a reference in the doc.

Tags: Database

Similar Questions

  • How can I allow one of my children to use local applications, while temporarily blocking his access to the Internet and while allowing children to continue to access the Internet?

    I have three children who have separate user accounts on our two computers. Both computers running Windows 7 Home Premium edition. We use Windows Live Family Safety on each computer to our parental controls for defining when and what each child can access. We used the period of parental control feature to block every child signed to computers, except when we allow. (It would be nice if we could block a computer and allow them to use the other.)

    However, I can't find a way to allow a child to not use the computer for local activities (for example, Microsoft Word), while blocking its access to the Internet. I also want to allow his brothers to continue to use the Internet during this time.

    Any help would be appreciated. Thank you.

    Hello

    Windows parental control have no option to directly block access to the internet in a Windows user account, because the system needs to provide activity reports. To work around the problem, you can block all internet browsers available for this user account so that the child have no way to access the internet. Restriction of the app to access the control that installed programs on the computer children.  Here are the detailed steps to block some apps:

    1. on any computer, log on to the parent account for http://fss.live.com

    2. click Edit settings under the name of the child you want to change the settings and then click the App restrictions.

    3. check the circle next to turn on the restrictions of the app.

    4. check all programs related to access to the internet or type the application in the area of Search apps .

    5. check the box next to the application or the program once it appears in the list.

    6. click on Save.

    This settings apply only to that specific user account. If you have any other questions, please let us know.

    Thank you!

  • Locking ESXi 4.1 mode access confirmation no access to the vCenter Server

    Hello

    ESXi 4.1.  I see options in conflict with access to a crowd that had lockdown normal mode activated via a server vCenter VM on a host in the cluster.  The vCenter server that sits on one of the hosts in the cluster lockeddown then became inaccessible or unresponsive connectivity wise.  So no connectivity between vCenter VM or VM vCenter and hosts.  Is someone can confirm if you can connect to this host lockedown by DCUI with root and disable lockdown configuration to allow the vSphere client to then connect to the host with root and troubleshoot the server vCenter VM?

    I read in some messages that this is only possible if the vCenter VM is in place and the communication to the host.  I also read that it is possible no matter what the State of the vCenter server once Total lockdown (disabling DCUI) is not enabled.

    I have this reference of the 'The new lock in ESXi 4.1 Mode' blog http://blogs.vmware.com/vsphere/2010/09/the-new-lockdown-mode-in-esxi-41.html

    "With active locking Mode, the only direct access to the host that remains open is through the DCUI. This allows to perform administrative tasks limited outside vCenter Server, such as restarting the management agents and the display of the log files. In addition, you can also disable Mode of Lockdown since the DCUI. This can be useful if vCenter Server is down or unavailable, and you want to return to a direct management of the host. Normally, without locking Mode, any user to the Administrator role can open a session in the DCUI.  However, in lock Mode, the root password is necessary; no other user can connect.

    Can anyone confirm.

    Any other person who may not be sure these questions, I can confirm that with root credentials, you can connect to the host directly and disable the lock mode regardless of the availability of vCenter.  Only if the Total lock mode turned on, or should I say DCUI is disabled, then you have no choice but to go through vCenter or reinstall and reconfigure the network.  VM would be always available if local or have to be reassembled and re inventoried etc.

  • ESXi 5.5 - Direct access to the local logical unit number

    I have a 5.5 stand-alone ESXi server.

    It has 2 local SAS controllers

    Controller 1 (HP Smart Array P410): data bank single RAID 10 with two VM's local logic unit number

    Controller 2 (HP Smart Array P812): only RAID 6 LUNS nothing on it yet...

    My question is that I need one of the virtual machine to access that LUN. Is it possible to give direct access to the VM to the controller and/or the unit number logic rather than create a vmdk and massive data store?

    If it is I know Flash would not work on these data, but that really doesn't matter in this case.

    Thank you

    Kenny

    Hi Kenny, and welcome to the communities,

    There is an article dealing with your situation KB: http://kb.vmware.com/kb/1017530

    Concerning

    Tim

  • vSwitch ESXi 5.1 workaround to virtual machines (direct access to the network)

    Hello world!

    I have a server running properly the 5.1 ESXi hypervisor and got inside the physical grid active router with DHCP. How can I configure the vSwitch on ESXi 5.1 work not managed on the network, without VLAN and have direct access to the network?

    Just to clarify, I would like to first of all virtual machines VMware Workstation works - if it is possible to run several virtual machines and define all NICS (Network Interface Card) as connected by a bridge, that is to say. Each VM gets the specific configurations of IP to the external router.

    Since now, thank you very much for the help!

    Best regards

    Eduardo

    With ESXi the vSwitches work comparable to Bridged networking, so there is really nothing special to do.

    André

  • connection of forms 6i with mysql without involving the Oracle Server

    Hi all

    could someone tell me how to connect forms 6i to mysql without involving the Oracle Server?

    allow to say that I have installed Developer 2000 oracle and install mysql 5.0.

    I open the form builder, click on connect.
    What must I provide here.
    I tried to create the named MYSQL odbc driver and try to connect you as below

    Scott/Tiger@ODBC:MySQL

    but it gives the error ORA-03121-none connected driver interface, works do not run.

    What should do?

    What you ask is impossible. Oracle Forms is designed to interact specifically with the Oracle database. You can access the other tables in the database in an Oracle using Oracle heterogeneous Services database, but right ODBC is no longer supported.

    Craig...

  • PIX 501 to allow access to the ftp server

    Hello

    We have a public ip address of the pix 501 and the other, I want to access the ftp server on the internal network from the outside. I tried to configure the PDM by a static nat, which translate to the address of the FTP to the public address, but then none of the stations networks could out - how can I configure it?

    I would also like to know what ports should I open on the acl for access to the ftp server.

    Thank you, daguech

    Yes, sorry... You must use the unique host for addresses command. The access list is applied to your external interface?

    for example, the command would be:

    Access-group acl_out in interface outside

    Also, can you connect to the local ftp server behind a firewall?

  • Do not have access to the oracle community ideas

    Hello

    Why don't I have access to the Oracle community ideas

    Ideas have been disabled by the administrator due to issues around spamming.  They hope it is resolved quickly so that the ideas can be relit.

  • access to the weblogic Server console problem

    Hi all

    We have a problem of access to the weblogic Server console page.

    We have fresh installed the Enterprise Manager Cloud control 12 c and we can access the MS pages without problems.

    When trying to connect to the weblogic Server (https:// < our_server >: 7101/console) with Firefox, IE11 or if the page is loading and loading without showing the login page.

    But when trying to connect to this address with a place (elinks) browser on the unix machine we'll see the first page immediately.

    Any ideas?

    Thank you

    Michael

    Hi all

    We solved the problem in another way: we opened the ports http access.

    Because issues were security settings in Internet Explorer.

    Thank you

    Michael

  • I want to log on without password to the oracle server

    I want to log on without password to the oracle server.

    by administrator user that I have installed the oracle database with that I can login without password, but by another user that I just can't!

    in windows server to oracle! a group with the name "oradba" exists in the windows group.

    any user who join the group to oradba can connect without a password

  • I have been a member of the CC, but had to leave for financial reasons. I have re installed my old version of CS6, but I get a pop up blocking my access to the program and telling me to renew my membership. What can I do?

    I have been a member of the CC, but had to leave for financial reasons. I have re installed my old version of CS6, but I get a pop up blocking my access to the program and telling me to renew my membership. What can I do?

    You are right!

    Try to uninstall the full CS6 using Adobe - Adobe CS5 Clean Tool and then install it via applications download Creative Suite 6

    Hope that helps!

  • DreamWeaver - has access to the customer server languages and scripts?

    DreamWeaver - has access to the customer server languages and scripts?

    Thanks to anyone who responds to this in advance.

    If the access you want to say, "can I write a JavaScript or PHP with Dreamweaver code?  Yes.

    If you mean something else, please provide details.

    Nancy O.

  • Exception sometimes when you send the query to the oracle server

    Hello

    I'll send the following query to the oracle server:
    t (*) AS 'COUNT' FROM 'DEPT_MANAGER' JOIN 'EMPLOYEES' ON DEPT_MANAGER. EMP_NO = EMPLOYEES. EMP_NO AND DEPT_MANAGER. TO_DATE = 9999-01-01' LEFT JOIN 'DEPT_EMP' ON DEPT_MANAGER. EMP_NO = DEPT_EMP. EMP_NO AND DEPT_EMP. TO_DATE = 9999-01-01' LEFT JOIN 'DEPARTMENTS"ON DEPT_EMP. DEPT_NO = DEPARTMENTS. DEPT_NO GROUP OF DEPARTMENTS. DEPT_NAME, EMPLOYEES. FIRST_NAME. » '|| EMPLOYEES. LAST_NAME, DEPT_MANAGER. EMP_NO, DEPT_MANAGER. DEPT_NO, DEPARTMENTS. DEPT_NO

    A java application, it works and another does not.
    Here are the exception?

    What can cause this? What does this exception?

    Message:-2
    Cause: null
    StackTrace
    oracle.jdbc.driver.T4CStatement.saveDefineBuffersIfRequired(T4CStatement.java:464)
    oracle.jdbc.driver.OracleStatement.prepareAccessors(OracleStatement.java:927)
    oracle.jdbc.driver.OracleStatement.executeMaybeDescribe(OracleStatement.java:1047)
    oracle.jdbc.driver.T4CStatement.executeMaybeDescribe(T4CStatement.java:830)
    oracle.jdbc.driver.OracleStatement.doExecuteWithTimeout(OracleStatement.java:1132)
    oracle.jdbc.driver.OracleStatement.executeInternal(OracleStatement.java:1687)
    oracle.jdbc.driver.OracleStatement.execute(OracleStatement.java:1653)

    Thank you

    To remove the suspected driver, download and use the latest ojdbc14.jar is.

  • howmany oracle user to connect with the oracle server.

    Hi all

    howmany oracle user to connect with the oracle server.
    I want to search for above sentence.

    Select the user name, count (*) from v$ session group by user name;

  • Blocks access to the http server homepage

    I can't seem to find how to block (or redirect away from) the Web Server home page.
    For example:
    A user accesses http://servername:7777 / pls/apex/f? p = 101:1 (a valid url)
    Then they come back to the end of the url to access http://servername:7777
    It's 'Welcome to the Oracle HTTP Server' page of my web server. How to block (or redirect away from) this page?
    I think it should be easy, but I can not find directions on how to do...
    Thank you

    You can change the index.htm file in the htdocs OHS_HOME to do a redirection of metatag like this:



    Or you could put a rule in the httpd.conf file.

    See: http://en.wikipedia.org/wiki/URL_redirection

    Thank you

Maybe you are looking for

  • -12H - Portege Z930 can't activate Windows 7

    Laptop comes with Windows 7 Pro 64 bit.Reason for the client software problems I decided to install Win 7 Pro 32 bit version. Everything is ok, but I can't use this Win 7 key to activate Windows. Activation procedure initially said that the Windows 7

  • SSL Tunneling Application outgoing failure

    Outgoing SSL Tunneling Application error Hello dear colleagues,I have UTM5 with the latest firmware. The unit works fine now with 3 VLANS / subnets, routing inter - VLAN, SSL VPN configuration, etc. I have an interesting question, but probably one of

  • difference ettus cards or

    Dear Sir/Madam What is the difference between NC and the native modules Ettus? Can Ettus modules be supported through LabVIEW, such as Council or USRP-2921? Thank you Concerning Albert

  • I CAN'T CONFIGURE MY EFAX ACCOUNT

    MY "CREATE A NEW ACCOUNT" OPTION IS GRAYED OUT AND IT DOES NOT RESPOND WHEN I CLICK TOP.  I HAVE NEVER SET UP AN EFAX ACCOUNT SO I DON'T HAVE A CONNECTION. HP TRIED TROUBLESHOOTING FOR ME AND COULDN'T DO. ANY HELP WOULD BE GREATLY APPRECIATED!  :-)

  • Check the level of ink Officejet 6210 with Windows 7

    Hello everyone,.. Since my above mentionned quest has not led to his term, only to the: "sorry, your search returned no matches. You can try a different search, or ask your question to the community. ", I'm here now.I look forward to an another KUDO