VLAN level intermediate and db

Hello

For the middle tier (soa) and DB is recommended to run on separate vlan or have on the same?

Our environment is ODAX4-2 and we intend to deploy SOA and DB on its individual VM and any help on best practices of vlan will help us.

Thank you

Hello

Depends to some extent on what you're trying to reach (safety or aid of the VLAN to allow some means enable quality of Service controls in your network).

  • We found that several levels of VLANS created some difficulties when using Plugins OEM such as the SOA Plugin - even if it was down to the Plugin not being able to see the correct networks - so if you have OEM in the network is it?
  • From a security perspective using the VLAN is good because it isolates the access in different levels, such as the mid range. But you must understand how your admins will get access to the servers if necessary. -If you have a data strategy then the data which will be held in the middle range and how secure you should be?
  • If you are planning a future where you could spend in the cloud, then using VPN will not be an option, I would suggest keep it simple and use alternative security strategies.

Hope this helps

Tags: Fusion Middleware

Similar Questions

  • With the help of Vlan for LAN and DMZ

    Hello

    For the moment, I have assigned my LAN and DMZ networks to two separate network card (so therefore no Vlan tagging)

    for example vmnic0 = LAN, vmnic1 = DMZ.

    It works well but I like to make changes in the way I want to use two separate physical network adapter and use on the two s two LAN and DMZ nic but now using the VLAN.

    So think of this configuration:

    For each network, I create a Vswitch, in order to obtain a Vswitch named VsLAN, VsDMZ for the case.

    The Vswitch I attribute a two nic Nic will be the day before. as vmnic0, vmnic2 (at rest)

    This Vswitch I create a port group and assign the correct number of VLan as LAN 10 and 20 to the DMZ.

    Create the another Vswitch will have the same Nic but now vmnic0 will be the stanby one.

    Probalby all great so far I think or not?

    Issues related to the:

    -Well this concept where there is a relationship a Vswitch and port group or a switch with multiple exchanges?

    In case a Vswitch with multiple port groups I will assign to group level reserve and the active NIC Port.

    -If I create a group of ports and assiging several Vlan IP packets received by the virtual machine itself also be labelled or not identified?

    Other words. Do I need to configure the NETWORK adapter to the virtual machine also for the same local network ID virtual or not.

    Thanks for your comments.

    Hello

    Change of vlan is a pretty good idea to get the failover and the performance of the network LAN and DMZ. You have confused somewhat however concepts.

    A can only be used in a vSwitch vmnic. So what you want to do is the following:

    Create a vSwitch

    On the vSwitch create two ports: LAN (vlan10), DMZ (vlan20)

    If vmnic0 and vmnic1 have access to the vlan10 and 20, then simply add the two vmnic virtual switch. By default, they will both be active and that's fine. If you do not want to CHANGE the GRPE ports LAN and goto the "failover" tab and put vmnic0 as active and vmnic1 as before. Then do the reverse on the DMZ port group.

    Best regards

    Frank Brix Pedersen

    blog: http://www.vfrank.org

  • How to disable, disable or reset the ink level warnings and messages

    I spent hours on the internet trying to figure out how to turn it off, disable or reset the ink level warnings and messages. The ink cartridges, I bought are not the expensive brands of HP, but generic print cartridges at a reasonable price. They work great, and I have no problem printing. But apparently HP went through a lot of trouble, making it difficult for customers to disable the annoying low ink level warnings that pester you every time that you try to print a page. It doesn't matter if the ink cartridges are completely full. It is obviously an attempt to punish consumers who buy anything other than HP products. I'm about to recant to never, EVER, buy another HP product again. I'm also about to post horrible comments on Amazon, Ebay, new egg and any other place I can think to warn potential clients of this heinous behavior of HP.

    Model: CN219A

    Serial number:[personal information deleted]

    Name: Series of HP Photosmart Plus B210e (network)

    Windows 7, the printer is on my wireless network.

    If anyone knows how to do this, let me know, before you take a hammer to my HP printer. Thank you

    Hi portaadonai,

    I want to help you with your ink pop up of disorders. Open this link by wade1027 on how to disable ink level notifications. You should be able to disable the pop out.

    Let me know if this helped.

    Thank you

  • VLAN voice N3048P and DHCP issues

    Hello

    I just received several switches for our N3048P and 2 x 4048 access layer - WE for our base layer. Are the N3048P VLT'd between two of 4048. There are 4 x N3048P of one on the other. The 4048 possess all gateways via VRRP.

    I have 802. 1 x works with my Windows client test, and I can get the phone (Cisco 7941) to acquire a DHCP address if I put it on a port "switchport mode access. However, if I change the port to a general port with vlan enabled voice and 802. 1 x, the phone does not have a DHCP address, but the PC attached to the phone Gets a DHCP address in the VLAN correct.

    I see CDP and LLDP messages exchanged via Wireshark, and it seems that the phone and the switch are to exchange the VLAN voice correctly.

    My question is, why the phone can't one address DHCP?

    Here's the relevant config of switch below. I know that some of the config can be duplicated for troubleshooting steps:

    VLAN 75
    the name 'Test '.
    output
    VLAN 76
    name "Test_Phones".
    output

    IP helper-address 1.1.1.3 dhcp
    IP helper-address 1.1.1.4 dhcp

    interface vlan 75
    IP 172.16.75.4 255.255.255.0
    IP helper 1.1.1.3
    IP helper 1.1.1.4
    output
    interface vlan 76
    IP 172.16.76.4 255.255.255.0
    IP helper 1.1.1.3
    IP helper 1.1.1.4

    AAA authentication local connection to "defaultList".
    radius of start-stop AAA accounting dot1x default
    control-dot1x system-auth
    radius AAA dot1x default authentication service
    AAA authorization network default RADIUS

    VLAN, VoIP

    source-ip 172.16.75.4 RADIUS server
    Server RADIUS 'key' key
    RADIUS-server host 1.1.1.1 auth
    primary
    name "rad1.
    use of 802. 1 x
    key 'key '.
    output
    RADIUS-server host 1.1.1.2 auth
    name "rad2.
    use of 802. 1 x
    key 'key '.
    output
    Server RADIUS acct 1.1.1.1 host
    name "rad1.
    output
    host server RADIUS acct 1.1.1.2
    name "rad2.
    output

    Gi2/0/1 interface

    Description '802. 1 x client port.
    spanning tree portfast
    spanning tree guard root
    switchport mode general
    switchport general allowed vlan add 75-76 the tag
    dot1x re-authentication
    dot1x quiet-period 5
    dot1x tx-period 5
    dot1x comments - vlan 20
    dot1x Informati-vlan 20
    LLDP transmit tlv ESCR-sys sys - cap
    LLDP transmit-mgmt
    notification of LLDP
    LLDP-med confignotification
    VLAN voice 76
    disable voice vlan auth
    output

    Thanks for any input you may have. I would like to know if there is any other information, I can provide.

    -Jason

    That ends up being the correct port configuration:

    Gi2/0/1 interface

    Description '802. 1 x client port.

    spanning tree portfast

    switchport mode general

    switchport General pvid 75

    VLAN allowed switchport General add 75

    switchport general allowed vlan add 76 tag

    dot1x port-control on mac

    dot1x re-authentication

    dot1x quiet-period 5

    dot1x timeout supp-timeout 15

    dot1x tx-period 5

    dot1x comments-vlan-deadline 15

    dot1x comments - vlan 20

    dot1x Informati-vlan 20

    VLAN voice 76

    disable voice vlan auth

    The most important line here is «the dot1x port-control on mac» I got 'auto control by port dot1x' configured, but it does not work as expected. In addition, defining the comments-vlan-period and supp-timeout were necessary. If the port was shot, the switch would not necessarily reauth port.

  • How VLANs ' IP subnet ing works with based port of VLAN (series N2000 and N3000)

    Hi all

    I have a small pile of x N3024 2 acting as my heart L3 with a lag of 2 x 10 g down to a stack of x N2048 5 acting as L2 switch for my PC workstations.

    Workstations are that all on the port assigned VLAN 10 (switchport access vlan 10). I have a bunch of developers who want to access without restrictions more or less to assign random IP addresses for their VM (Virtualbox and VMware) Workstation.  As you can imagine, I would like some control over this situation.  the powerconnect guide I described features of subnet IP VLAN but does not seem to enter in how it works and interacts with the port actually function vlan assignments.

    What I currently have is the VLAN 10 assigned to a segment that support the subnet 172.100.x.x which dates back to our base of L3 for routing to other segments. What I want to do is to configure the VLAN based on IP and then load the dev is to config their VM with another IP range, say 10.10.x.x.

    Theory here is, I set the L3 core with say 20 VLAN and an IP to register in L3 path between subnets and then configure the battery switch L2 workstation with IP - based VLAN to recognize 10.10.x.x and separate on VLAN 20.

    However, I think the simplified here question is if I have a nail up to 10 ports VLAN, will the than basic work IP subnet VLANS as I want only it? Or, I need to create a subnet IP VIRTUAL local area network for the two IP ranges? I have to remove the assignenment VLAN per port and are based entirely on the treatment of subnet IP VLAN?

    If there is a better RTFM on this topic you can tell me I would appreciate it

    Thank you!

    I ended up calling specialists... great Dell technical support here.

    In fact, the IP based VLAN works very close to what I want to achieve. Missing from the user guide is that the port needs to be in the mode. Ports using switch port mode and bound to a VLAN just didn't work... probably because the vlan IP based did not differ from the port binding. Dell support has suggested to use the trunk mode, but my answer is finished using the general mode; any traffic not referenced, PVID located my usual LAN vlan ID and acceptance of port traffic of new vlan based on IP. In this way, I'm able to have a physical host DHCP on the corporate LAN and a virtual machine on that host to bind to a different subnet which is then isolated in the new NAV based on IP.

  • How the level 0 and level 1 backups are related?

    Version: 11 g

    I was going through the scripts in the post, two issues related to the RETENTION STRATEGY


    When you have a differential incremental backup strategy and when you run scripts to backup of level 1 and level 0 via cronjobs different from Sunday to Saturday, during recovery, how RMAN will identify all these level 1 backups and backup of level 0 parent as a single unit? In level 0, and its backup scripts later level 1, I do not see a clause that links the level 0 backup and its subsequent backups level 1?

    Hi Steve_74,

    How RMAN will identify all these level 1 backups and backup of level 0 parent as a single unit?

    Information used during a restore comes the controlfile.

    Example of
    Select backup, INCREMENTAL_LEVEL
    v $ backup_set
    /
    Will determine the backup set level 0 necessary depending on your clause of restore

    Select INCREMENTAL_LEVEL, INCREMENTAL_CHANGE #, CHECKPOINT_CHANGE #.
    v $ BACKUP_DATAFILE
    When file # = 1
    /
    Will determine what (s) to apply to the datafile 1 according to your restoration clause.

    Kind regards

    Tycho

    Edited by: tychos on November 1st, 2009 01:51

  • What is the need for level 0 and level 1 backup?

    I am a bit confused about the need for level 0 and level 1 backup. Oracle has proposed strategy in 10g creates only level 1 backup continues to not to break and not to create any level of 0 after the first backup of level 0. But I had seen in the document Oracle Database Backup & Recovery basis he suggests to create backup of level 0 on weekly or monthly basis. There?

    Secondly according to my understanding when creating oracle backup of level 1 first creates a level 0 backup that contain also copies of data image files and then apply an incremental copies of the image, once the incremental backup is applied on the copy of the image you don't have to the previous incremental backups. Am I wrong?
    If I'm right, what is the difference between level 0 & backup of level 1? and after the level 0 backup you must also all previous backups.

    PL. help me to clarify my questions in this regard.

    Kind regards

    Vassallo

    What is the most reliable in terms of recovery?

    I do not see the differences in terms of recovery, the two strategies are reliable.

    There is an advantage in terms of recovery time expected, Oracle says:

    /*
    Incorporate gradually update the backup in your backup strategy shortens the time of recovery as provided. The reason is that media recovery right now or at some point in the recent past may begin at the time of the last backup of level 1 applied, rather than at the time of the last full database backup.
    */

    In a regular incremental backup strategy you always go back to a level 0 backup and then to apply everything follows level 1 backups + archivelogs. But - for an incremental backup set to day - it's a little tricky to emerging a window of recovery, normally relies on redundancy 1, i.e. that a backup is retained, you cannot go back, this type of backup is designed for a quick and complete recovery.

    But there is a solution (I don't think there is place in EM), even if you're on 10g, see the 11 g documentation, he explains fuller:

    http://download.Oracle.com/docs/CD/B28359_01/backup.111/b28270/rcmbckba.htm#BRADV89532

    Werner

  • reference level range and vertical

    What is the relationship between the reference level range & scope vertical?

    Alann Hello,

    High-speed digitizers help NOR is very useful in the definition of these types of words.

    Help ' reference levels are high, low and mid range values you set for take the time to climb, descent, positive width, negative width, positive cycle duty and report negative cyclical measures.» Reference levels are usually set up in terms of percentage of the wave, that you purchase. By default, the low value is 10% of the wave, the average level is 50% and the high value is 90%."

    Also of scanners high speed OR help "vertical range is the duration of the peak to peak voltage a digitizer that can measure the level of input connector.» Most scanners have several choices for the vertical range. »

    The only relationship between these two concepts is in the fact that the vertical range defines the peak values of the signal input, which also limits your reference levels of high and low.

    If you have not installed the driver NOR-Scope, but still want to reference the help file is available for download here.

  • Noise levels dropped and I lost clarity after updates installed recently

    latest updates of XP have cause the sound levels on my audio to drop and lack of power

    I play a lot of theatre organ music, and after one of the massive mocrosoft updates, the lack of power and clarity.  It's loose!  Before I couls break blisters if I chose to do this now my 240w surround sounds no better than a good pair of desktop speakers!  If everything again and reinstall XP, I am disable automatic updates permanently!  He was playing beautifully until he forced 80 updates on me.  The sound was great before that!  I was not even allowed to choose what updates I tried, as an icon appears on the stop button, telling me he was going to install these updates when I shut down the computer.

    My motherboard is a Gigabyte MA790X-UD4P
    Processor is an AMD 1090 t BE
    Audio is onboard Realtek ALC889A with latest drivers installed
    Operating system is Windows XP - Pro 2002, upgraded to SP3

    I also tried a dedicated high-end Creative Labs sound card, and the problem is still there!  Please do not recommend I have upgrade to Win7, because I already bought it, and as far as I am concerned, it stinks!  Bling, for the little ones!  a lot of my software will not work on it, and I am not spending thousands of dollars to replace that I just want what I have and everything to work properly.

    Sincerely,
    Russ

    Whoa, there!

    Loser sound after a big update happens, unfortunately. My recommendation to you is to let the MS to update your PC then cracks at least safe and warts have disappeared. Before turning off automatic updates if you feel you must.

    Afterwards , re - install your audio drivers.

    You say you tried a card Creative - is still in the PC? With its drivers? Bad move.

    (BTW, Creative are NOT the cards pro audio, whatever they say.) The EMU is the name of their pro cards division. That being said, they write just drivers for their playing cards and "hifi", which are not expensive. )

    I think you're the best solution is to stick with the Creative (its better than Realtek) card. Here's what I'd do:

    (1) download the giving drivers and software for your Creative device if you don't already have them.

    (2) uninstall all the drivers/software related to an audio device (Realtek, Creative, Sound Blaster etc.) via Device Manager and the software part of XP.

    (3) re-boot,

    (4) when you hear a beep from your PC, go into the BIOS (you need to read the manual that came to know which key to press). Most of the time repetedly pressing DELETE will get you in there.

    (5) can disable the onboard sound and save and exit.

    (6) starts. XP is it and you want to install the drivers, don't let it.

    (7) when everything has calmed down, install the Creative and the sofware drivers.  Re-starting as a precaution after the installation.

    If you don't do the above, you will get a conflict between your card on board and the creative map that can cause symptoms similar to what you describe, and are not easy to diagnose and solve remotely.

    W7 is a different way of thinking, is everything. Each to his own. Personally, I stuck with it and am more than satisfied with its functionality. But as I said, everyone has his own ;-)

    FYI, there are Vista and XP sp3 compatibility modes in W7 to this software that does not work 'out of the box' in W7. If you want help on knowledge which of your programs will or won't work, re-post and I'll try and help you.

    Hope this helps, good luck,

    Jerry

  • PowerConnect 5448 several VLANS between upstream and downstream server firewall

    I am struggling with what I thought, would be a simple task: route several subnets, each on one VLAN different, a firewall to a server.  In fact, I can't even pass the VLAN by default one still looking correct in the address tables and STP.

    Port 1 = firewall, VLAN 1 unidentified, 2 VLAN Tag, 1 PVID, tried the two trunk and general patterns

    17 = server NIC, VLAN 1 unidentified port, VLAN Tag, PVID 1 and 2 2, tried, tried both safe and general patterns

    VLAN 1 (firewall untagged) 10.84.195.0/24, 10.84.195.2 Interface IP and default gateway 10.84.195.1

    VLAN 2 (tag of firewall) 10.101.0.0/16, IP Interface 10.101.0.2 for 2 VLAN, firewall est.1

    The first thing I got was that something has not been properly marked by (Hyper-V, using SC VMM 2012 SP1) server or the firewall (Watchguard XTM 520).  Simple test: VPN Firewall, ping the switch to 10.101.0.2 with the tag, and works, remove the label and it doesn't.  Dynamic address table shows the two-way firewall.  Line 18 below appears right after the ping as planned on VLAN 2 with the same MAC address in VLAN 1.  In addition, I ping the switch 10.101.0.2 from the server and it works fine.  The table shows that VLAN 2 from the host (and 1 other VM), so it seems to me that everything is properly labeled.


     
    15 VLAN 1 00907f8f571b G1    
      16 VLAN 2 00155d1f1b07 G17    
      17 VLAN 2 001dd8b71c01 G17    
      18 VLAN 2 00907f8f571b G1    
     

    What I can't do, is ping through the switch to VLAN 2.  I can't ping my VPN server (10.101.20.1), and I can not ping to the gateway (10.101.0.1) from the server.  Note, it is not because of rules to firewall on each end.

    What Miss me?  I don't think I need a routing of layer 3 here, I don't have to go through VLAN, just have them several VLANS passes from one port to the other.

    Other things to note in case it is useful:

    -I have no connectivity not tag with everything else through the 10.84.195.xxx/24 switch.

    -If I delete the Tags VLAN port 2 1 trunk, I suddenly can ping the bridge VLAN 2 (10.101.0.1) from the server, although I suspect that it is because the same port is the default gateway for the switch.

    -For brevity, only 2 lines of the STP are listed below, but all ports are therefore based on the question of whether they are connected or not.

    G1 activated 128.1 Frw Desg P2P (STP) No. 4
    G2 activated 128.2 Dsbl Dsbl No. 100.

    -Latest firmware installed.

    -In addition, for people concerned about their security, I want to remove use VLAN by default in the future.

    Would it be possible for run you to stick your show output here in the forum.  In this way, we can take closer look at what you have configured.

    If you connect a desktop/laptop computer (with and intellectual property in the 10.101.0.0/16 range) in a port with the mode of access switchport VLAN 2 are you able to ping IP Interface 10.101.0.2 for 2 VLANS?  You could try to disconnect the firewall and the configurations for the port and work on getting through the switch with 2 terminals on a single VLAN.  Then, once this is confirmed as work connect the firewall back up with a trunk/general mode adding the VLAN necessary.

    You connect to the firewall on a layer 3 interface?  You need Layer 3 routing to reach the firewall correctly.

  • VLAN protected port and voice

    When protected switchport is configured on a switchport (3750G switch), is what affects him vlan voice as well? I currently have protected ports configured, but we'll be adding IP phones soon and would prefer not to have to disable ports protected to allow phone phone voice traffic. I found on cisco.com where a port in a vlan voice can be a protected port, but it does not say if the traffic of phones on the switch is blocked or allowed, just that it can be configured on a protected Harbor.

    Thanks for any assistance on this.

    Thank you

    Mark

    Hello

    By default, all traffic on a 'protected switchport' interface will be sent for the uplinks. This includes all voice traffic and data from this particular interface.

    However, there is a work around available according to your configuration. There is a layer 2 isolation between ports, all traffic to these ports are sent to the uplinks and must be routed from one port to another, even though they may be in the same VLAN. A router is connected to running "proxy arp local' (or local-proxy-arp ip) can respond to ARP requests for IP addresses in a subnet where normally no routing is necessary."

    Depending on the connected device, you can have an able to use the local proxy arp feature to get around this VLAN voice. It should be an L3 device with the available command. 3750's take on support this command.

    Hope this helps

    -Joe

  • Dynamic assignment of the NAC to the same vlan came on and off strip

    Hello

    Pls forgive my ignorance, I'm fresh in the biz of the NAC.

    I have a requirement for a client, very large high rising with numerous hospital, they want to assign MDs to the same vlan, if he or she uses the Office at out clinic, which would be OOB Layer 3, and even he or she uses the Tablet PC/PDA wireless during the round room.

    The question is whether this is something achievable. A little trick how to do it would be very useful.

    Appreciate your expertise.

    Thank you

    Saami

    By user role VLAN can be activated for OOB.

    The VIRTUAL LAN is configured on the role and setting up OOB, there is a check box that you need to activate so that the user receives the vlan configured on the role (I don't remember the exact section now..).

    With that, whenever a user who belongs to a specific role connects, he will receive the same VLAN according to what is set up on its role.

    I hope this helps.

  • Where to add the transitional attribute at the level of the entities or view level? And where to use {return getTransientAttribute()} in the entity or view?

    Mr President

    JDev 12.2.1.

    Where to add the transitional attribute at the level of the entities or view level?

    And where to use {return getTransientAttribute()} in the entity or view?

    public Number getAmount()  
      {  
        return getTransientAttribute();  
        //return (Number) getAttributeInternal(AMOUNT);  
      }  
    
    

    Concerning

    A difference I could think: place a transient attribute on EO level will make transaction dirty (DBTransaction.isDirty returns true) when the field is changed.

    From a design point of view, I tend to place the transient fields at the level VO, because most of the time they are for the presentation of the data in the user interface.

    Only when the transient fields are involved in DML operations (for example when you call a stored procedure EntityImpl.doDML) I place the transitional area on EO.

  • low-level genarts and Sapphire exception error

    Hi guys,.

    for about one or two weeks, I get "exception of low level error" messages whenever I try to use a sapphire or transition effect.

    Had no problem before, so I'm really curious.

    Tempted to go Cuda cl only, open software

    deleted manytimes caches

    and even uninstalled first and reinstalled.

    Still having this issue.

    My system is a Macbook Pro retina 15 '' running Mavericks and first Pro CC 9.2.0

    The Sapphire is v9.02

    I hope someone can help me!

    Got a solution of GenArts support!

    If anyone happens to have the same questions,

    Here is the info:

    Open the file/Library/Application Support/GenArts/SapphireAE/s_config.text with a text editor.

    Find the line that says "use_gpu: Yes" and to take "use_gpu: no" and save the file.

    Then restart the first and see if that fixes it.

    The only thing I find my s_config.text file in this folder: Applications/GenArtsSapphireAE/config

  • R12.1.3 - question on db level cloning and oraInventory

    R12.1.3 on Linux RH 5.8 64-bit.

    I cloned an instance of Prod to go through the application Jan 2014 PSU etc.  It comes to take the DB of 11.2.0.3.5 to 11.2.0.3.9.

    Which seemed to work ok once I understood what I had to do (previous post that revealed that I had to restore a few patches).

    Now, I want to run through this process again and after cloning this instance once more I found that my order "opatch lsinventory" tells me that I'm already patched to the level of the power supply.

    I tried to rebuild my oraInventory via $ORACLE_HOME/oui/bin/attachHome.sh, then ouicli.pl, but in both cases, he tells me that I'm already at 11.2.0.3.9.

    So is this a case of my $ORACLE_HOME is not being rebuilt as part of the update?

    My cloning process is scripted and I use RMAN with a double active command I am running «adcfgclone.pl dbTechStack»  I think these are the relevant entries while I also update fnd_profile_option_values etc. and fnd_concurrent_requests.  Finally, it then executes adautocfg.sh.

    I have to do something more to get an own ORACLE_HOME?  What is my problem?

    Why do you still have files in the former $ORACLE_HOME on the target node?

    Please change inventory_loc "inventory_loc = / app/oracle ', remove all files that belong to this instance (including oraInventory), runs to go ahead with the cloning process (preclone, copy all files, postclone).

    Thank you

    Hussein

Maybe you are looking for