IBM Guardium

IBM Guardium

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  S-TAP with Exadata PDB/CDB

    Posted Mon July 01, 2024 05:39 PM

    Hi all,

    Any of you has a Guardium installation monitoring working well with Oracle Exadata PDB/CDB (plugable database) on OCI?

    If yes, which Guardium version you´re using?  Are there some settings that I need to play attention?

    Regards,

    Rodrigo



    ------------------------------
    Rodrigo Xavier
    ------------------------------


  • 2.  RE: S-TAP with Exadata PDB/CDB

    Posted Thu August 22, 2024 01:28 PM

    We do have S-TAP configured and running. It works well for all of the non-encrypted traffic. However, we are trying to capture encrypted traffic using A-TAP and we have not been able to do so. Have you been able to monitor PDB/CDB with Guardium?



    ------------------------------
    Deependra Adhikari
    ------------------------------



  • 3.  RE: S-TAP with Exadata PDB/CDB

    Posted Thu August 22, 2024 02:07 PM
    Hi Deependra,

    We´re collecting the data with no encrytion, no problem.
    But with encryption, even if with A-TAP enabled, we can´t collect the data.  We´re with a IBM PME opened about this case.

    Regards,

    Triscal Consultoria

    Rodrigo Xavier
    Coordenador de Consultoria
    Segurança da Informação e Privacidade
    Rio de Janeiro (21) 2507-2010
    São Paulo (11) 3167-0526
    www.triscal.com.br






  • 4.  RE: S-TAP with Exadata PDB/CDB

    Posted Tue August 27, 2024 10:39 AM

    Hi Rodrigo - Same here, we worked with IBM Support and they were able to unblock us from the issue. In our case, it basically came down to authorizing additional (all) users to guardctl and removing load balancers (ELB) from configuration. By default we had only authorized oracle and grid users. We are now able to monitor encrypted traffic as well.



    ------------------------------
    Deependra Adhikari
    ------------------------------



  • 5.  RE: S-TAP with Exadata PDB/CDB

    Posted Wed August 28, 2024 01:45 PM
    Hi Deependra!

    Cool!
    But can you detail how perform guardctl command to authorizing users?
    The ELB is disabled.

    Regards!!

    Triscal Consultoria

    Rodrigo Xavier
    Coordenador de Consultoria
    Segurança da Informação e Privacidade
    Rio de Janeiro (21) 2507-2010
    São Paulo (11) 3167-0526
    www.triscal.com.br