Onboarding Oracle Database to Recovery Service
Use checklists to review the mandatory requirements, and plan to onboard your Oracle Database to Recovery Service.
-
Mandatory Requirements Checklist for Recovery Service
Use this checklist to verify the mandatory prerequisites to onboard your Oracle Database to Recovery Service. -
Optional Configuration Checklist for Recovery Service
You may choose to configure these additional options for Recovery Service. -
Recovery Service Resource Limits
A service limit is the quota or allowance set on a resource. Autonomous Recovery Service has maximum limits for the number of protected databases and the backup storage space utilization. The limits apply to each region. -
Optional Permissions for Oracle Databases in OCI
By default, Oracle Databases in OCI are assigned with the permissions to access Recovery Service. The service can also access the network resources within the database VCN. You may choose to assign the additional and optional permissions for OCI Databases, as described in this topic. -
Permissions Required for Oracle Multicloud Databases to Use Recovery Service
Assign Recovery Service IAM policies that allow Oracle Multicloud Database to send backups to Recovery Service. -
Configuring Network Resources for Recovery Service
Create or use an existing IPv4-only subnet for Recovery Service operations in the database VCN. Define security rules to control the backup traffic between your database and Recovery Service. -
Registering the Recovery Service Subnet
Use this procedure to register a Recovery Service subnet. -
Ways to Manage Recovery Service Resources
In Oracle Cloud Infrastructure (OCI), you can create and manage Recovery Service resources using a variety of interfaces provided to fit your different management use cases.
Mandatory Requirements Checklist for Recovery Service
Use this checklist to verify the mandatory prerequisites to onboard your Oracle Database to Recovery Service.
Note
Note: Operational backups to two different backup destinations may create data loss scenarios. Therefore, before you enable automatic backups to Recovery Service, you must disable manual backup scripts and processes to other storage destinations.
Table 3-1 Mandatory Requirements for Onboarding your Database to Recovery Service
| Check | Task |
|---|---|
| Ports used by Recovery Service | You must open these network ports and configure the security rules for Recovery Service.
|
| Security rules for Recovery Service | Use Security Lists or network security groups (NSGs) to configure the security rules.
See Subnet Size and Security Rules for Recovery Service Subnet for details. For Oracle Multicloud Databases, you must use network security groups (NSGs) to define the security rules and associate the NSGs (maximum five) while registering the Recovery Service subnet. |
| Supported platform | Linux x86-64 |
| Target database compatibility level | 19.0.0 or later Ensure that the target database compatibility level (the |
| Supported Oracle Database releases | Oracle Cloud Databases and Oracle Multicloud Databases You can set Autonomous Recovery Service as the backup destination for Oracle Cloud Databases and Oracle Multicloud Databases provisioned with any of these releases:
On-Premises Oracle Databases You can add on-premises Oracle Databases provisioned with any of these releases to Recovery Service.
See Add On-Premises Database to Recovery Service Using Cloud Protect for details. Oracle Database Releases that Support Recovery Service on Government Cloud |
| Recovery Service resource limits | Ensure that the Recovery Service resource limits are adequate and request for an increase in service limits, if necessary. For Oracle Multicloud Databases, you must review and adjust the limits specific to your multicloud subscription from the Limits, Quotas and Usage page in the OCI Console. Caution: If you do not select the multicloud subscription, then the increased limits will be applied to OCI resources.See Recovery Service Resource Limits for details. |
| Recovery Service IAM policies |
See Permissions Required for Oracle Multicloud Databases to Use Recovery Service for details. |
| Database encryption | If you are backing up on-premises Oracle Database to Recovery Service, then the TDE wallet must be setup and open irrespective of whether TDE is configured for the database. If pluggable databases (PDBs) use local TDE wallets, then the local TDE wallets must be open. This is required for encrypting backups to Recovery Service. For more information, refer to these sections in the Transparent Data Encryption Guide:
Caution: Oracle strongly recommends to use an external key management system, such as Oracle Key Vault. Storing the decryption keys on the same server as the encrypted data allows database server attacks to potentially gain access to the keys and the database. Encrypted backups cannot be recovered if the keys are compromised or stolen.See Protecting On-premises Databases using Oracle Database Zero Data Loss Cloud Protect for detailed steps to add on-premises databases to Recovery Service. |
| DNS resolution | If you are adding an on-premises Oracle Database to Recovery Service, then a DNS Listener is required to accept DNS requests from the on premises network. The DNS Listener will be used to resolve the Recovery Service backup IP addresses. The FQDN must be registered with the Recovery Service subnet. See Protecting On-premises Databases using Oracle Database Zero Data Loss Cloud Protect for detailed steps to add on-premises databases to Recovery Service. |
| Recovery Service subnet for Oracle Databases in OCI | For OCI Databases, such as Oracle Exadata Database Service on Dedicated Infrastructure and Oracle Base Database Service, Recovery Service automatically registers the Recovery Service subnet when you enable automatic backups.
Choose one of these options:
|
| Recovery Service subnet for Oracle Multicloud Databases | For an Oracle Multicloud Database, if you have used a network security group (NSG) to implement security rules for Recovery Service in the database VCN, then you must add the Recovery Service NSG to the Recovery Service subnet. The recommended subnet size is /24. See Register a Recovery Service Subnet for details. Recovery Service supports these Oracle Multicloud Database services:
|
| SBT Library for on-premises Oracle Databases | The Cloud Protect Fleet Agent requires the SBT library file For Oracle Database 19.27 or later versions and Oracle AI Database 26ai Release Update 23.8 or later versions, the For Oracle Database 19.26 and earlier versions, ensure to download the See Protecting On-premises Databases using Oracle Database Zero Data Loss Cloud Protect for details. |
Related Topics
Optional Configuration Checklist for Recovery Service
You may choose to configure these additional options for Recovery Service.
Table 3-2 Optional Configuration Checklist for Recovery Service
| Check | More Information |
|---|---|
| Protection policy options |
|
| IAM users and groups to manage Recovery Service resources | As a tenancy administrator, you can create IAM users and groups to manage Recovery Service related tasks. You can then assign Recovery Service policy statements to the groups. For example, create a group called |
Related Topics
Recovery Service Resource Limits
A service limit is the quota or allowance set on a resource. Autonomous Recovery Service has maximum limits for the number of protected databases and the backup storage space utilization. The limits apply to each region.
Table 3-3 Autonomous Recovery Service Resource Limits
| Resource | Oracle Universal Credits | Pay As You Go or Trial |
|---|---|---|
| Autonomous Recovery Service Protected Database Count | Contact Us | Contact Us |
| Autonomous Recovery Service Space Used for Recovery Window (GB) | Contact Us | Contact Us |
Use the console to review the current service limits and usage information, and request an increase in resource limits, if necessary.
-
In the navigation menu, select Governance & Administration, and then select Tenancy Management.
-
Select Limits, Quotas and Usage.
-
Select Autonomous Recovery Service from the Service list.
Review the current limits and usage information.
-
Request a service resource limit increase, if necessary. For Oracle Multicloud Databases, ensure to review and adjust the limits specific to your multicloud subscription from the Limits, Quotas and Usage page.
Caution: If you do not select the multicloud subscription, then the increased limits will be applied to OCI resources.
-
(Optional) You can also control the resource utilization within compartments. See Quota Policy Quick Start for detailed information.
Related Topics
Optional Permissions for Oracle Databases in OCI
By default, Oracle Databases in OCI are assigned with the permissions to access Recovery Service. The service can also access the network resources within the database VCN. You may choose to assign the additional and optional permissions for OCI Databases, as described in this topic.
Note:
Recovery Service includes separate IAM policy templates for Oracle AI Database@Azure, Oracle AI Database@Google Cloud, and Oracle AI Database@AWS.
If you are configuring Recovery Service for your Oracle Multicloud Database, then skip this section and proceed to Permissions Required for Oracle Multicloud Databases to Use Recovery Service.
To assign the optional permissions for OCI Databases:
-
In the Policy Builder, select Autonomous Recovery Service as the Policy Use Case.
-
Select the policy templates or add the policy statements using the manual editor in the Policy Builder. (see Table 3-4, Table 3-5, and Table 3-6)
Table 3-4 Additional Permissions in the Ability to do all things with Autonomous Recovery Service Policy Template
| Policy Statement | Create In | Purpose |
|---|---|---|
Allow service database to manage tagnamespace in tenancy |
Root compartment | Enables the OCI Database Service to access the tag namespace in a tenancy. If you assign this permissions, then a protected database can inherit the tags from the source database. |
Allow group admin to manage recovery-service-family in tenancy |
Root compartment | Enables users in a specified group to access all Recovery Service resources. Users belonging to the specified group can manage protected databases, protection policies, and Recovery Service subnets. |
Table 3-5 Let users manage protection policies in Autonomous Recovery Service
| Policy Statement | Create In | Purpose |
|---|---|---|
Allow group {group name} to manage recovery-service-policy in compartment {location} |
Compartment that owns the protection policies. | Enables all users in a specified group to create, update, and delete protection policies in Recovery Service. |
Consider this example.
This policy grants the RecoveryServiceUser group with the permissions to create, update, and delete protection policies in ABC compartment.
Allow group RecoveryServiceUser to manage recovery-service-policy in compartment ABCThe Let users manage Autonomous Recovery Service subnets policy template
Table 3-6 Let users manage Autonomous Recovery Service subnets
| Policy Statement | Create In | Purpose |
|---|---|---|
Allow Group {group name} to manage recovery-service-subnet in compartment {location} |
Compartment that owns the Recovery Service subnets. | Enables all users in a specified group to create, update, and delete Recovery Service subnets. |
Consider this example.
This policy grants the RecoveryServiceAdmin group with the permissions to manage Recovery Service subnets in ABC compartment.
Allow group RecoveryServiceAdmin to manage recovery-service-subnet in compartment ABCRelated Topics
Permissions Required for Oracle Multicloud Databases to Use Recovery Service
Assign Recovery Service IAM policies that allow Oracle Multicloud Database to send backups to Recovery Service.
In the Policy Builder, select Autonomous Recovery Service as the Policy Use Case, and then assign one of these policies that is relevant to your Oracle Multicloud Database.
Oracle AI Database@Azure
Let Oracle AI Database@Azure use Autonomous Recovery Service for backup
Allow service database to manage tagnamespace in tenancy
Allow group admin to manage recovery-service-family in tenancy
Allow service database to use organizations-assigned-subscription in tenancy
where target.subscription.serviceName = 'ORACLEDBATAZURE'ORACLEDBATAZURE indicates the service name for Oracle AI Database@Azure.
Oracle AI Database@Google Cloud
Let Oracle AI Database@Google Cloud use Autonomous Recovery Service for backup
Allow service database to manage tagnamespace in tenancy
Allow group admin to manage recovery-service-family in tenancy
Allow service database to use organizations-assigned-subscription in tenancy
where target.subscription.serviceName = 'ORACLEDBATGOOGLE'ORACLEDBATGOOGLE indicates the service name for Oracle AI Database@Google Cloud.
Oracle AI Database@AWS
For an existing OCI tenancy, use the policy builder’s manual editor to add these policy statements required for Oracle AI Database@AWS to back up to Recovery Service. For a new OCI tenancy, these permissions are assigned by default.
Allow service database to manage tagnamespace in tenancy
Allow group admin to manage recovery-service-family in tenancy
Allow service database to use organizations-assigned-subscription in tenancy
where target.subscription.serviceName = 'ORACLEDBATAWS'ORACLEDBATAWS indicates the service name for Oracle AI Database@AWS.
Related Topics
Configuring Network Resources for Recovery Service
Create or use an existing IPv4-only subnet for Recovery Service operations in the database VCN. Define security rules to control the backup traffic between your database and Recovery Service.
Note:
For Oracle Multicloud Databases, ensure to register the backup subnet as the Recovery Service subnet. The recommended subnet size is /24.
Recovery Service supports these Oracle Multicloud Database services:
- Oracle Database@Azure
-
Oracle Database@Google Cloud
- Oracle Database@AWS
Network ports 2484 and 8005 enable the network connectivity between Oracle Database@AWS and Recovery Service. In an existing OCI tenancy, ensure to open the network ports 2484 and 8005. In a new OCI tenancy, the same network ports are open by default for Oracle Database@AWS.
When you onboard an Oracle Database@AWS resource to Recovery Service, the service automatically registers the backup subnet as the Recovery Service subnet. You can either use the Recovery Service subnet that is automatically registered by the service or register your own Recovery Service subnet.
About Using a Private Subnet for Recovery Service Operations
Recovery Service requires a private subnet in the same virtual cloud network (VCN) where your database resides. The private subnet must include security rules to control the backup network between your database and Recovery Service.
Recommendations for Recovery Service Subnets in the Database VCN
-
Your database VCN must have a single private subnet for backups to Recovery Service. The private subnet must reside in the same VCN where the database resides.
-
Select an IPv4-only subnet for Recovery Service in your database VCN. Do not select an IPv6-enabled subnet as Recovery Service does not support using an IPv6-enabled subnet. See Creating a Subnet to learn more.
-
The recommended subnet size is
/24(256 IP addresses).Recovery Service dynamically assigns the required number of free IP addresses to support the private endpoints. If you have any limitations on the available number of free IP addresses, then use a minimum
/27subnet size which will allow 32 IP addresses.You can either create a new private subnet or select any preexisting subnet (of the recommended size) available in the database VCN.
For Oracle Exadata Database Service on Dedicated Infrastructure, by default, the backup subnet is used for Recovery Service operations. For Oracle Base Database Service, the database subnet is also used for backing up to Recovery Service.
-
When you enable automatic backups to Autonomous Recovery Service, the service automatically registers the private subnet as a Recovery Service subnet. You can either use the automatically registered Recovery Service subnet or register your own Recovery Service subnet.
If you have used network security groups (NSGs) to implement the security rules, then you must associate the Recovery Service NSGs to the Recovery Service subnet. See Register a Recovery Service Subnet for details.
-
If a Recovery Service subnet contains insufficient number of available IP addresses, then Recovery Service issues an alert message when you try to add a new database. In this scenario, you can add IP addresses by associating multiple subnets to the Recovery Service subnet. See Add or Replace Subnets for a Recovery Service Subnet.
-
Your Oracle Cloud database can reside in the same private subnet used by Recovery Service or in a different subnet within the same VCN.
Note
Note: Oracle recommends using a private subnet for backups to Recovery Service. However, it is possible to use a public subnet.
Implementing Security Rules for Recovery Service Subnet
The database VCN requires security rules to allow backup traffic between your database and Recovery Service.
Security rules for the Recovery Service subnet must include stateful ingress rules to allow destination ports 8005 and 2484.
Use these Networking service features to implement security rules:
-
A security list allows you to add security rules at the subnet level.
In your database VCN, select the security list that is used for the Recovery Service subnet, and add the ingress rules to allow destination ports 8005 and 2484.
-
Network Security Groups (NSG)
Network security groups (NSG) enable granular control over security rules that apply to individual VNICs in a VCN. Recovery Service supports these options to configure security rules using NSGs:-
Create one NSG for the database VNIC with egress rules to allow ports 2484 and 8005. Add a separate NSG for Recovery Service with ingress rules to allow ports 2484 and 8005. Use this approach if you want to implement network isolation.
-
Create and use a single NSG (with egress and ingress rules) for the database VNIC and Recovery Service.
-
Note:
-
If you use network security groups (NSG) to implement security rules or if your database VCN restricts network traffic between subnets, then ensure to add an egress rule for ports 2484 and 8005 from the database NSG or subnet to the Recovery Service NSG or subnet that you create.
-
If you have created NSGs to implement the security rules, then you must associate the Recovery Service NSG to the Recovery Service subnet. See Registering the Recovery Service Subnet for details.
-
If you have configured a security list and an NSG within your database VCN, then the rules defined in the NSGs takes precedence over the rules defined in a security list.
See Comparison of Security Lists and Network Security Groups to learn more.
Related Topics
Review Networking Service Permissions to Configure a Subnet
Ensure that you have these Networking Service permissions required to create a subnet in the database VCN and to assign security rules for Recovery Service.
Table 3-8 Networking Service Permissions Required to Create a Private Subnet and Configure Security Rules for Recovery Service
| Operation | Required IAM Policies |
|---|---|
| Configure a private subnet in a database VCN |
|
Alternatively, you can create a policy that allows a specified group with broader access to networking components.
For example, use this policy to allow a NetworkAdmin group to manage all networks in any compartment in a tenancy.
Example 3-1 Policy for Network Administrators
Allow group NetworkAdmin to manage virtual-network-family in tenancySubnet Size and Security Rules for Recovery Service Subnet
The security rules are necessary to allow backup traffic between a database and Recovery Service.
Note:
-
Select an IPv4-only subnet for Recovery Service in your database VCN. Do not select an IPv6-enabled subnet as Recovery Service does not support using an IPv6-enabled subnet. See Creating a Subnet to learn more.
-
You can use network security groups (NSGs) to control the traffic for the Recovery Service subnet. Security rules must include stateful ingress rules to allow destination ports 8005 and 2484.
Table 3-9 Subnet Size and Security Rules for the Recovery Service Subnet
| Item | Requirements |
|---|---|
| Recommended subnet size | /24 (256 IP addresses) If you have any limitations on the available number of free IP addresses, then use a minimum /27 subnet size which will allow 32 IP addresses. |
General ingress rule 1: Allow HTTPS traffic from Anywhere |
This rule allows backup traffic from your Oracle Cloud Infrastructure Database to Recovery Service.
|
General ingress rule 2: Allows SQLNet Traffic from Anywhere |
This rule allows recovery catalog connections and real-time data protection from your Oracle Cloud Infrastructure Database to Recovery Service.
|
Note
Note: If you use network security groups (NSG) to implement security rules or if your database VCN restricts network traffic between subnets, then ensure to add an egress rule for ports 2484 and 8005 from the database NSG or subnet to the Recovery Service NSG or subnet that you create.
Create a Recovery Service Subnet in the Database VCN
Use the OCI Console to configure a private subnet for Recovery Service in your database virtual cloud network (VCN).
Note:
For Oracle Multicloud Databases, ensure to register the backup subnet as the Recovery Service subnet. The recommended subnet size is /24.
Recovery Service supports these Oracle Multicloud Database services:
-
Oracle Database@Azure
-
Oracle Database@Google Cloud
-
Oracle Database@AWS
Network ports 2484 and 8005 enable the network connectivity between Oracle Database@AWS and Recovery Service. In an existing OCI tenancy, ensure to open the network ports 2484 and 8005. In a new OCI tenancy, the same network ports are open by default for Oracle Database@AWS.
When you onboard an Oracle Database@AWS resource to Recovery Service, the service automatically registers the backup subnet as the Recovery Service subnet. You can either use the Recovery Service subnet that is automatically registered by the service or register your own Recovery Service subnet.
-
In the navigation menu, select Networking, and then select Virtual cloud networks to display the Virtual Cloud Networks list page.
-
Select the VCN in which your database resides.
-
Use these steps to create a Recovery Service subnet with a security list. If you want to use network security groups, then proceed to [step 4].
-
On the details page for the virtual cloud network, select the Security tab.
-
Under Security Lists, select the security list that is used for the VCN.
-
On the details page for the security list, select the Security rules tab.
You must add two ingress rules to allow destination ports 8005 and 2484.
-
Select Add Ingress Rules and add these details to set up a stateful ingress rule that allows HTTPS traffic from anywhere:
-
Source Type: CIDR
-
Source CIDR: Specify the CIDR of the VCN where the database resides.
-
IP Protocol: TCP
-
Source Port Range: All
-
Destination Port Range: 8005
-
Description: Specify an optional description of the ingress rule to help manage the security rules.
-
-
Select +Another Ingress Rule and add these details to set up a stateful ingress rule that allows SQLNet traffic from anywhere:
-
Source Type: CIDR
-
Source CIDR: Specify the CIDR of the VCN where the database resides.
-
IP Protocol: TCP.
-
Source Port Range: All
-
Destination Port Range: 2484.
-
Description: Specify an optional description of the ingress rule to help manage the security rules.
Note
Note: Select an IPv4-only subnet for Recovery Service in your database VCN. Do not select an IPv6-enabled subnet as Recovery Service does not support using an IPv6-enabled subnet. See Creating a Subnet to learn more.
See: Subnet Size and Security Rules for Recovery Service Subnet for more information.
-
-
-
Select Add Ingress Rules.
-
On the details page for the virtual cloud network page, select the Subnets tab and then select Create Subnet.
-
Create a private subnet or select a private subnet that already exists in the database VCN. Oracle recommends a subnet size of /24 (256 IP addresses) for the private subnet.
-
On the details page for the subnet, select the Security tab. Under Security Lists, add the security list that includes the ingress rules to allow destination ports 8005 and 2484.
Note
Note: If your database VCN restricts network traffic between subnets, then ensure to add an egress rule for ports 2484 and 8005 from the database subnet to the Recovery Service subnet that you create.
-
-
Use these steps to create a Recovery Service subnet with network security groups (NSG).
-
On the details page for the virtual cloud network, select the Security tab and go to the Network Security Groups section.
-
Select Create Network Security Group.
Use one of these supported methods to configure security rules using NSGs:
-
To implement network isolation, create one NSG for the database VNIC (add egress rules to allow ports 2484 and 8005) and a separate NSG for Recovery Service (add ingress rules to allow ports 2484 and 8005).
-
Create and use a single NSG (with egress and ingress rules) for the database VNIC and Recovery Service.
The Network Security Group page lists the NSGs that you create.
-
-
Note:
-
For OCI Databases, Recovery Service automatically registers Recovery Service subnet.
You can either use the Recovery Service subnet registered by the service or register your own Recovery Service subnet.
-
If you have implemented security rules using NSGs, then you must register the Recovery Service subnet by adding the Recovery Service NSGs (maximum five).
-
Oracle recommends that you register only a single Recovery Service subnet per VCN.
-
For additional configuration details, refer the relevant OCI Database Service documentation.
Registering the Recovery Service Subnet
Use this procedure to register a Recovery Service subnet.
Note:
Before you register a Recovery Service subnet:
-
Ensure to open these network ports and configure the security rules for Recovery Service.
-
Port 2484 - Enables SQL*Net connections to the RMAN catalog which is used by Recovery Service.
-
Port 8005 - Enables backup traffic from the database to Recovery Service.
-
-
Ensure that you have reviewed and confirmed the mandatory prerequisites described in Mandatory Requirements Checklist for Recovery Service.
-
Ensure that you select an IPv4-only subnet for Recovery Service operations in your database VCN. Do not select an IPv6-enabled subnet as Recovery Service does not support using an IPv6-enabled subnet.
-
For Oracle Databases deployed in OCI, if your backup subnet meets the recommended subnet size (at least 12 free IP addresses), then Recovery Service automatically registers the Recovery Service subnet. If you want to replace the subnet registered by Recovery Service, use the steps described in Add or Replace Subnets for a Recovery Service Subnet.
-
If you have used network security groups (NSG) to implement the security rules for Recovery Service in the database VCN, then you must add the Recovery Service NSGs (maximum five) to the Recovery Service subnet, as described in step 8. The recommended subnet size is /24.
Recovery Service supports these Oracle Multicloud Database services:
-
Oracle AI Database@Azure
-
Oracle AI Database@Google Cloud
-
Oracle AI Database@AWS
Network ports 2484 and 8005 enable the network connectivity between Oracle AI Database@AWS and Recovery Service. In an existing OCI tenancy, ensure to open the network ports 2484 and 8005. In a new OCI tenancy, the same networks ports are open by default for Oracle AI Database@AWS.
When you onboard an Oracle AI Database@AWS resource to Recovery Service, the service automatically registers the backup subnet as the Recovery Service subnet. You can either use the Recovery Service subnet that is already registered by the service or use the steps provided in this section to register your own Recovery Service subnet.
-
-
Multiple protected databases can use the same Recovery Service subnet. In order to ensure that the required number of IP addresses are available to support the Recovery Service private endpoints, you can assign multiple subnets to a Recovery Service subnet that is used by more than one protected database.
-
On the Recovery Service subnets list page, select Register Recovery Service subnet. See Listing Recovery Service Subnets for detailed steps to access the list page.
-
Enter a name for the Recovery Service subnet. Avoid entering confidential information in the Name field.
-
Verify the compartment where you want to create the Recovery Service subnet. Use the Create in compartment field to select a different compartment, if necessary.
-
Select the Compartment that contains the virtual cloud network (VCN) that you want to use. You can select a VCN from only one compartment at a time.
-
Select the virtual cloud network.
-
Under Subnets, select these options:
-
Select the Compartment that contains the private subnet that you want to use.
-
Select the Subnet that you have configured for Recovery Service operations in the selected VCN.
-
-
(Optional) Select +Another Subnet to assign an additional subnet to the Recovery Service subnet.
If a single subnet does not contain enough IP addresses to support the Recovery Service private endpoints, then you can assign multiple subnets. See About Using a Private Subnet for Recovery Service Operations for details.
-
Expand Advanced options to configure these options:
-
Network security groups
If you have used network security groups (NSG) to implement the security rules for Recovery Service in the database VCN, then you must add the Recovery Service NSGs (maximum five) to the Recovery Service subnet. The Recovery Service NSG can reside in the same compartment or in a different compartment. However, the NSG must belong to the same VCN to which the specified subnet belongs.
Use these steps to add the Recovery Service NSG to the Recovery Service subnet:
-
In the Network security groups section, select Use network security groups to control traffic.
-
Select the Recovery Service NSG you have created in the database VCN.
-
Select +Another network security group to associate multiple NSGs (maximum five).
-
-
Security attributes
(Optional) In the Security attributes section, you can add security attributes to restrict access to the Recovery Service subnet. See Managing Security Attributes for Recovery Service Subnet for details.
Note
Note:
-
If you have permissions to create a resource, then you might also have permissions to add security attributes to that resource. To add a security attribute, you must have permissions to use the security attribute namespace. For more information about security attributes and security attribute namespaces, see Zero Trust Packet Routing. If you are not sure whether to add security attributes, skip this option or ask an administrator. You can add security attributes later.
-
If an endpoint has a Zero Trust Packet Routing (ZPR) security attribute, traffic to the endpoint must satisfy ZPR policies and also all NSG and security list rules. For example, if you are already using NSGs and you add a security attribute to an endpoint, all traffic to the endpoint is blocked. From then onward, a ZPR policy must explicitly allow traffic to the endpoint.
-
-
Tags: (Optional) Add one or more tags to the resource. If you have permissions to create a resource, then you also have permissions to apply free-form tags to that resource. To apply a defined tag, you must have permissions to use the tag namespace. For more information about tagging, see Resource Tags. If you are not sure whether to apply tags, skip this option or ask an administrator. You can apply tags later.
-
-
Select Register.
Note
Note: A Recovery Service subnet must be associated with at least one subnet belonging to your database VCN.
You can replace a subnet or add more subnets to support the required number of private endpoints. See Add or Replace Subnets for a Recovery Service Subnet for details.
See Associate NSGs to a Recovery Service Subnet for detailed steps to add NSGs to an existing Recovery Service subnet.
Ways to Manage Recovery Service Resources
In Oracle Cloud Infrastructure (OCI), you can create and manage Recovery Service resources using a variety of interfaces provided to fit your different management use cases.
| Interface | More Information |
|---|---|
| OCI Console | Using the Console |
| Application Programming Interfaces (APIs) | Oracle Database Autonomous Recovery Service API |
| Command-Line Interfaces (CLIs) | Using the CLI |
Related Topics