2 Oracle SDM Cloud Deployment Process and Procedures

Obtaining and Installing the Oracle® Session Delivery Management Cloud (Oracle SDM Cloud) service requires a multi-step process that includes tasks for you to perform in the Oracle Cloud and on premises. New customers must take steps to establish and set up their Oracle Cloud account in addition to the procedures for installing the Oracle SDM Cloud service. See the following topics to guide you through the process.
  • Oracle SDM Cloud Deployment Process
  • Establish an Oracle SDM Cloud Service Subscription
  • Login to Oracle SDM Cloud to obtain inputs for Management Cloud Engine (MCE)
  • Establish a site with the Oracle SDM Cloud's Registration ID to which the Management Cloud Engine (MCE) can connect
  • Install, Configure, and Activate the MCE

Oracle SDM Cloud Deployment Process

The high-level process for deploying the Oracle® Session Delivery Management Cloud (Oracle SDM Cloud) includes the following steps. You will pierform some steps in the Oracle Cloud and others on-premises.
  1. Oracle Cloud—Contact your Oracle Cloud sales representative to establish a subscription for Oracle SDM Cloud and activate your Oracle Cloud and Oracle Identity Cloud Services accounts.
  2. Oracle Cloud—Login to Oracle SDM Cloud and obtain the Identity and Access Management (IAM) for inputs to Management Cloud Engine (MCE).
  3. Oracle Cloud—While logged into Oracle SDM Cloud, create a site. Once created, select the site to edit and obtain the generated site Registration ID to use for MCE inputs.
  4. On premises—Install the Management Cloud Engine (MCE) with the install, activate, and configuration scripts provided in the software download.

    The following diagram illustrates the deployment process and shows the parameters you need to set in each Oracle SDM Cloud component to establish the service.

    This diagram depicts the Oracle SDM Cloud infrastructure.

Supported Regions

Oracle® Session Delivery Management Cloud (Oracle SDM Cloud) supports deployment in two OCI Regions, Ashburn (IAD) and Frankfurt (FRA).

Within these two regions, users select a home region, which is where IAM resources are defined.

Oracle SDM Cloud supports the IAM domain home region to any of the following Ashburn deployment regions.

Region Name Region Location
Canada Southeast (Montreal) Montreal, Canada
Canada Southeast (Toronto) Toronto, Canada
US East (Ashburn) Ashburn, VA
US West (Phoenix) Phoenix, AZ
US West (San Jose) San Jose, CA

Oracle SDM Cloud supports the IAM domain home region to any of the following Frankfurt deployment regions.

Region Name Region Location
Germany Central (Frankfurt) Frankfurt, Germany
Netherlands Northwest (Amsterdam) Amsterdam, Netherlands
Switzerland North (Zurich) Zurich, Switzerland

Establish an Oracle SDM Cloud Service Subscription

To obtain the Oracle® Session Delivery Management Cloud (Oracle SDM Cloud) service, contact Oracle Cloud Sales to purchase a Cloud Services Agreement and the Oracle SDM Cloud service description.

Establishing an Oracle SDM Cloud service subscription is a multi-step process. Use the information provided in the following links to guide you through the process.
  1. Go to https://docs.oracle.com/en/cloud/paas/identity-cloud/index.html for information about how to purchase a subscription to Oracle SDM Cloud.
  2. Go to https://docs.oracle.com/en/cloud/get-started/subscriptions-cloud/index.html for information about how to activate your Oracle Applications account order.
  3. Go to https://www.oracle.com/webfolder/technetwork/tutorials/obe/cloud/getting_started/create_cloud_account_admin_obe/create_cloud_acc_admin.html for information about how to manage your Oracle Cloud services.

Obtain the IAM Inputs for MCE

To connect the Oracle® Session Delivery Management Cloud (Oracle SDM Cloud) to the Management Cloud Engine (MCE), you must login to the Oracle SDM Cloud and obtain the Identity and Access Management (IAM) parameters.
  1. Log on to the Oracle SDM Cloud using the URL that you received in your "Welcome" email from Oracle.
  2. Browse to Security Manager, IAM.
    The Identity Access Management page displays showing the unique identifiers for the following components:
    • Oracle SDM Cloud FQDN
    • Oracle SDM Cloud Tenant ID
    • IDCS FQDN
    • IDCS Tenant ID
    • MCE IDCS Client ID
    • MCE IDCS Client Secret

Create a Site and Retrieve Generated ID for MCE Inputs

To connect the Oracle® Session Delivery Management Cloud (Oracle SDM Cloud) to the Management Cloud Engine (MCE), you must login to the Oracle SDM Cloud, create a Site, and retrieve the Generated ID for MCE inputs.
  1. Logon to the Oracle SDM Cloud using the URL that you received in your "Welcome" email from Oracle.
  2. Browse to Device Manager, Sites.
    The Sites page displays.
  3. Click Add, enter a Site name and optionally a Description and click Apply.
    The Sites page displays showing the newly added Site.
  4. Select the Site and click Edit.
    The Edit Site page displays with a Site ID with a unique identifier.
  5. Use the Site ID when adding your MCE in Oracle SDM Cloud.

MCE Host Installation

The host VM running the Management Cloud Engine (MCE) must use Oracle Linux 9.x as its operating system.

Use the following steps to install the Oracle Linux 9 installation image (ISO) on a bare-metal VM.
  1. Download the Oracle Linux 9 ISO.
    1. Log in to Oracle Software Delivery Cloud.
    2. Search for Oracle Linux.
    3. Select REL: Oracle Linux 9 (latest)
    4. Set Platform to x86 64 bit.
    5. Download the ISO.
  2. Upload the downloaded ISO to the ESXi datastore.
    1. In the ESXi host client, open Storage (or Datastore browser, depending on version).
    2. Upload the downloaded OL9 ISO to a location such as the datastore ISO folder.
  3. Create a new virtual machine.
    1. Log in to the VMware Host Client.
    2. Navigate to Virtual Machines, Create / Register VM (or Create a VM, depending on version).
    3. Select Create a new virtual machine and provide values in the following fields:
      • Name—Enter a meaningful name for the VM.
      • Guest OS Family—Enter Linux.
      • Guest OS Version—Enter Oracle Linux 9 (64-bit)
      • Storage type—Select Standard.
      • Datastore—Select the datastore where you uploaded the ISO.
    4. Configure Virtual hardware as required for your deployment.
    5. Attach the ISO.
      • Set CD/DVD Drive to Datastore ISO file.
      • Browse to and select the uploaded Oracle Linux 9 ISO
      • Ensure Connect at Power on is selected.

        This opens the installation page.

  4. Install Oracle Linux 9.
    This screenshot shows an example of the Oracle Installation page.

    1. Power on the VM.
    2. In the console, select Install Oracle Linux 9.
    3. Follow the installer, using defaults unless otherwise required.
  5. Select your software.
    1. Open Software Selection.
    2. Under Base Environment, select Server.
    3. Under Additional Software, select Remote Management for Linux.
    4. Select Done.
  6. Configure installation destination and partitioning.
    1. Open Installation Destination.
    2. Select Custom storage configuration and select Done.
    3. Under Manual Partitioning, use the plus (+) icon to create the required mount points, and select Done.
    4. Confirm any partitioning changes when prompted.
  7. Perform network configuration (recommended before installation)
    1. Open Network & Host Name.
    2. Enter the Host Name.
    3. Set the network interface to On.
    4. Click Configure and set your required IPv4 details.
    5. Ensure connectivity by configuring the following fields:
      • DNS Servers
      • Search domains (under the IPv4 Settings tab)
    6. Select Save, then Done.
  8. Begin the installation.
    1. Click Begin Installation.
    2. Complete any required prompts (for example, set root password or create an admin user), if requested.
    3. After installation completes, reboot and log in.
Configure Two Network Interfaces

You can configure two NICs (LAN and WAN) either before installing Oracle Linux 9 (recommended) or after.

  1. In the ESXi Host Client, select the VM and click Edit (Edit settings).
  2. Click Add other device, Network Adapter (or Add network adapter).
  3. Configure the second adapter with the name Network Adapter 2 and enter any required details.
  4. Select Save.
  5. Assign the new IP to the interface using the following command:
    sudo ifconfig <INTERFACE_NAME> 192.x.x.x netmask 255.x.x.x up
  6. Use the ifconfig command to verify the new interface is added.

Using Base Environment: Server with Additional software: Remote Management for Linux installs key components that commonly include Podman, Perl, and SNMP utilities, along with other base and management packages.

The following table lists the key packages installed:
Purpose/Function Key Packages (Examples)
Base system glibc, coreutils, util-linux, bash, filesystem
Remote management cockpit*, openssh*, sssd*, realmd, net-snmp*
Automation ansible-core, dnf*, yum
Cloud/Container podman*, buildah, open-vm-tools, virt-what
Device/storage/tools lvm2*, xfsprogs, udisks2*, device-mapper*
Security/SELinux selinux-policy*, firewalld, audit*, rsyslog*
Monitoring sos, tuned, strace, procps-ng
Python & Perl python3*, perl*
Compression/utility tar, unzip, zip, rsync, wget
Internal libraries libgcc, zlib, libstdc++, libxml2, openssl-libs

Note:

Package names may vary slightly by update level and repository configuration.

Install and Configure the MCE

The Management Cloud Engine (MCE) installation procedure requires the archive file containing the installation and configuration scripts that you downloaded from Oracle onto your host hardware. Oracle recommends running the two scripts consecutively in one session the first time you install the MCE. For that reason, this procedure includes the prerequisites and steps for running both scripts.

MCE Installation Prerequisites

Do the following before performing the procedure.

System Prerequisites
  • Ensure that the host meets operating system and resource requirements.
  • Operating System Oracle Linux 9 or higher or Red Hat compatible Kernel

    Note:

    The latest version of Oracle SDM Cloud is not tested on Red Hat Enterprise Linux (RHEL) and Oracle recommends using the base version of Linux on the 9.x release.
  • Install Perl V5.32.1 or higher on the host.
  • Install Podman v5.4.0 or higher on the host.
  • Download the archive file (mce-<version>.tgz) from My Oracle Support (MOS) to the host server. This .tgz file includes all necessary scripts.

    Note:

    MCE activation, configuration, and deactivation no longer require root privileges. Root access remains mandatory for the installation, uninstallation, and upgrades.
Installation Script Prerequisites
  • Ensure that there is no MCE installation existing on the hardware. See the last step in this procedure for instructions.
  • Ensure that you have root access.
Configuration Script Prerequisites
  • Note the MCE WAN IP, MCE LAN IP, and MCE name.
  • Navigate to Oracle® Session Delivery Management Cloud (Oracle SDM Cloud) Security Manager, IAM page to configure IAM parameters.

Procedure

The following procedure provides instructions for installing the MCE initially and for re-installing the MCE later, for example, in a disaster recovery scenario.

Note:

Before re-installing, you must first uninstall the existing MCE.
  1. Unpack the mce-<version>.tgz archive.
    tar -xvzf mce-<version>.<build>.tgz
    The system creates the mce-<version> directory and copies the unpacked files there in the following directory tree.
    mce-<version>.<build>/
    mce-<version>.<build>/mce/
    mce-<version>.<build>/mce/perl/
    mce-<version>.<build>/mce/perl/activate.pl
    mce-<version>.<build>/mce/perl/deactivate.pl
    mce-<version>.<build>/mce/perl/uninstall.pl
    mce-<version>.<build>/mce/perl/config.pl
    mce-<version>.<build>/mce/perl/changeloglevel.pl
    mce-<version>.<build>/mce/perl/showversion.pl
    mce-<version>.<build>/mce/perl/collectinfo.pl
    mce-<version>.<build>/mce/perl/helper.pl
    mce-<version>.<build>/mce/cfg/
    mce-<version>.<build>/mce/cfg/mce.properties
    mce-<version>.<build>/mce/cfg/version
    mce-<version>.<build>/mce/cfg/log4j2.xml
    mce-<version>.<build>/mce/cfg/log4j2_debug.xml
    mce-<version>.<build>/mce/cfg/tenantState.properties
    mce-<version>.<build>/mce/cfg/registeredMceNF
    mce-<version>.<build>/mce/cfg/container-mce.service
    mce-<version>.<build>/mce/ssl/
    mce-<version>.<build>/mce/ssl/fra-preprod-ca-chain.cert1.pem
    mce-<version>.<build>/mce/ssl/fra-prod-ca-chain.cert1.pem
    mce-<version>.<build>/mce/ssl/iad-ca-chain.cert1.pem
    mce-<version>.<build>/mce/logs/
    mce-<version>.<build>/mce/img/
    mce-<version>.<build>/mce/img/mce.tar
    mce-<version>.<build>/mce/hdrData/
    mce-<version>.<build>/mce/processedHdrData/
    mce-<version>.<build>/mce/export/
    mce-<version>.<build>/mce/export/audit-export/
    mce-<version>.<build>/mce/export/audit-export/keys/
    mce-<version>.<build>/install.pl
    mce-<version>.<build>/upgrade.pl
  2. Log on to the server at root. Ensure the user logging in has the proper Linux permissions.
  3. Run the install.pl script.
    ./install.pl
    -------------------------------------------------------------------------------
    Oracle Communications Management Cloud Engine, (c) 2026 Oracle
    MCE v26.1.0.0.2 install.pl @ 2026-07-27 12:00:59
    -------------------------------------------------------------------------------
    Checking pre-conditions...
    Ok.
    Proceed with install (y/n) : y
    Installing mce to /opt/oracle ...
    Installation successful.
    [abcd@acme123 mce-1.0.0]$
    The system checks for an existing MCE instance in Podman.
    • If it exists, the script execution stops and you must uninstall it.
    This creates the /oracle/mce directory under /opt. (If an oracle directory already exists, the install creates an MCE directory only.)
  4. From /opt/oracle/mce/perl, run the config.pl script and configure the attributes according to your environment.
    -------------------------------------------------------------------------------
    Oracle Communications Management Cloud Engine, (c) 2026 Oracle
    MCE v26.1.0.0.2  @ 2026-07-27 10:46:01
    -------------------------------------------------------------------------------
    Checking pre-conditions...
    The following inputs are required for MCE to register with Oracle SDM Cloud:
    MCE Host Name               : cgbu-phx-347
    Host WAN IP Address         : 100.77.50.195
    Host LAN IP Address         : 10.196.248.92
    Oracle SDM Cloud FQDN       : <From IAM page>
    Oracle SDM Cloud tenant ID  : <From IAM page>
    IDCS tenant ID              : <From IAM page>
    MCE IDCS client secret      : <From IAM page>
    Oracle SDM Cloud Site ID    : <From Device manager → Sites>
    Enable proxy(y/n)           : y
    Proxy server address        : 100.77.50.145
    Proxy server port           : 3128
    --------------------------------------------------------------------
    The following inputs are required for MCE KeyStore configuration:
    MCE TLS Key Store Password   :
    MCE TLS Key Store Password   confirm :
    --------------------------------------------------------------------
    The following inputs are required for MCE operation:
    Trap Receiver Port        : 162
    --------------------------------------------------------------------
    Ready to process inputs
    Proceed with configuration (y/n) : y
    This creates a mce.properties file under /opt/oracle/mce/cfg, which contains all of the information entered in config.pl.
  5. From /opt/oracle/mce/perl, run the activate.pl script to activate the MCE.

    Note:

    The MCE activation script also creates a systemd service, allowing users the ability to configure the MCE container to restart every time the VM reboots. This service is removed when the deactivate script is run.
    ./activate.pl
    -------------------------------------------------------------------------------
    Oracle Communications Management Cloud Engine, (c) 2026 Oracle
    MCE v26.1.0.0.2  @ 2026-07-27 12:49:22
    -------------------------------------------------------------------------------
    Checking pre-conditions...
    Ok.
    MCE tomcat port:7070, Trap receiver port:2000
    Proceed with activate (y/n) : y
    Activating container mce...
    Start to run container mce, image id fb90a2c4b930 ...
    Container mce with image id fb90a2c4b930 started.
    
    Do you wish to auto restart MCE after VM reboot? (y/n): y
    Creating Service for MCE auto start …
    [sudo] password for aiskamat:
    Activation successful!
  6. (Optional) Check your work with Podman.
    1. At the prompt type: podman images, and press Enter to list the MCE instances. Under TAG look for <version> <build> which is the new installation. The following table shows an example.
      % podman images
    2. At the prompt type: podman ps, and press Enter to list the running images. In the list, under "NAMES", look for "mce". Under STATUS, look for the newest one of each. The following code block shows an example.
      % podman ps
  7. (Optional) From /opt/oracle/mce/perl, run the deactivate.pl script to deactivate the MCE.
    Running the deactivate script removes the systemd service that automatically restarts the MCE when the VM reboots.
    ./deactivate.pl
    -------------------------------------------------------------------------------
    Oracle Communications Management Cloud Engine, (c) 2026 Oracle
    MCE v26.1.0.0.2  @ 2026-07-27 12:49:22
    -------------------------------------------------------------------------------
    Checking pre-conditions...
    Ok.
    Proceed with deactivate (y/n) : y
    Start deactivation
    
    Stopping container: mce ...
    Container mce stopped.
    
    Removing volumes with image: mce ...
    Volumes for container mce removed.
    
    Removing image with id: fb90a2c4b930 ...
    Image with id: fb90a2c4b930 removed.
    
    Removing auto-start mce service....
    Deactivation Success!
  8. (Optional) Run the following commands to manage the container-mce.service:
    • To check the service's status when running the MCE as a non root user:
      systemctl --user status container-mce.service
    • To check the service's status when running the MCE as a root user:
      sudo systemctl status container-mce.service

      Enter the password when prompted.

    • To disable the service when running the MCE as a non root user:
      systemctl --user disable container-mce.service
    • To disable the service when running the MCE as a root user:
      sudo systemctl disable container-mce.service

      Enter the password when prompted.

Traffic Flow and Firewall Port Recommendations

The following table provides traffic flow and firewall port recommendations for communication between the Management Cloud Engine (MCE) and Network Functions (NFs).

Port Number Protocol Service Configurable Purpose
161 UDP SNMP Y SNMP traffic between the MCE and the NF.
162 UDP SNMP Y SNMP trap reporting from the device to the MCE server.
22 TCP SFTP/SSH N Used for secure file transfer (for example, software upgrades, Route Manager, and LRT updates) and SSH sessions between MCE and southbound NFs.
3001/3000 TCP ACP/ACLI N Used by the MCE to communicate with all versions of a NF.
443 TCP HTTPS N Usec by MCE to communicate with Media Engines (MEs).
Upgrading the MCE

To upgrade the Management Cloud Engine (MCE), download the MCE upgrade archive from My Oracle Support (MOS) to the MCE host.

Before you begin, ensure that you have root access to the MCE host. For information about other installation prerequisites, see Install and Configure the MCE.
  1. Log in to the MCE host as the root user.
  2. Deactivate the currently installed MCE.
    /opt/oracle/mce/perl/deactivate.pl

    When prompted, enter y to continue. The script stops the MCE container, removes its associated volumes and image, and removes the MCE auto-start service.

  3. Download the latest MCE archive from My Oracle Support.
  4. Extract the archive.
    tar -xvf mce-<version>.<build>.tgz
  5. Change to the directory created when you extracted the archive.
    cd mce-<version>.<build>
  6. Run the upgrade script.
    ./upgrade.pl

    The script verifies that an MCE installation exists in /opt/oracle/mce, that the MCE is not active, and that the upgrade path is supported. When the validation succeeds, enter y to continue with the upgrade.

  7. Activate the upgraded MCE.
    /opt/oracle/mce/perl/activate.pl

    When prompted, enter y to activate the MCE. To configure the MCE to start automatically after the virtual machine reboots, enter y when prompted to create the auto-start service. Enter n if you prefer to start the MCE manually after each reboot.

During the upgrade, persistent data such as configuration properties and artifacts created when the MCE registers with Oracle SDM Cloud are copied to the new installation. The previous installation is moved from /opt/oracle/mce to /opt/oracle/mce.bak, and the upgraded installation is placed in /opt/oracle/mce.

Configure MCE Behind NAT or Firewall

Oracle® Session Delivery Management Cloud (Oracle SDM Cloud) allows you to configure the Management Cloud Engine (MCE) to operate behind a Network Address Translation (NAT) or a firewall. Oracle SDM Cloud contacts the MCE using the value for the mce.ip in mce.properties or wan-ip on setting up ./config.pl configuration.

The MCE supplies the mce.ip value when it registers with Oracle SDM Cloud. You can set the mce.ip value as a static IP address that maps to the NAT public interface or firewall. For example:
 mce.ip : 10.x.x.x 
Oracle SDM Cloud always uses port 443 for these connections, requiring any device placed between the MCE and Oracle SDM Cloud to dedicate port 443 to the MCE for all possible IP addresses.

Note:

The MCE does not have proxy support between itself and devices.
Manage MCE Traps

Oracle® Session Delivery Management Cloud (Oracle SDM Cloud) provides trap filtering at the Management Cloud Engine (MCE) level. This allows administrators to prevent specific SNMP traps from being processed based on defined criteria, such as the source IP address or the trap name.

Trap filtering is configured through a trap-filter.json file located on the MCE.

When a trap is received, MCE evaluates it against the configured filters. If the trap matches any of the specified criteria, it is excluded from further processing.

The filter configuration supports multiple source IP addresses and trap names. Administrators can enable or disable filtering by modifying the trap-filter.json file and restarting the MCE for the changes to take effect.

The following table lists and describes the supported filter types:
Filter Type Description
trapName Excludes traps matching the specified trap name. Note that trap names are case-sensitive.
sourceIp Excludes all traps received from the specified source IP address. Note that only IPv4 is currently supported.

Note:

Although both are referred to as filters, MCE-level trap filters and Fault Manager filters behave differently:
  • MCE-level filters block matching traps from being processed or forwarded.
  • Fault Manager filters allow matching traps to be forwarded to configured receivers.

For information on adding and removing trap filters at the MCE level, see Add a Trap Filter At the MCE Level and Remove a Trap Filter at the MCE Level in Getting Started.

Add a Trap Filter At the MCE Level
To configure trap filtering on the Management Cloud Engine (MCE):
  1. Navigate to the trap filter configuration directory.
    cd /opt/oracle/mce/cfg/trapfilter
  2. Open the trap filter configuration file.
    vi trap-filter.json
  3. In the trapfilterList array, add one or more filter objects. Each object must include:
    • filterType—Specifies the filter criteria (trapName or sourceIp)
    • value—The corresponding trap name or source IP address to filter
      For example:
      {
        "trapFilterList": [
          { "filterType": "trapName", "value": "linkDown" },
          { "filterType": "sourceIp", "value": "100.77.41.61" }
        ]
      }
  4. Save the file.
  5. Restart the MCE for the changes to take effect.
    ./deactivate.pl
    ./activate.pl

Note:

In high availability (HA) deployments, include both the primary and secondary IP addresses when configuring filters to ensure traps from both nodes are handled consistently.

For additional details, examples, and validation rules, see the README file located in /opt/oracle/mce/cfg/trapfilter.

Remove a Trap Filter At the MCE Level
To remove an existing trap filter on the Management Cloud Engine (MCE):
  1. Navigate to the trap filter configuration directory.
    cd /opt/oracle/mce/cfg/trapfilter
  2. Open the trap filter configuration file.
    vi trap-filter.json
  3. Locate the filter entry you want to remove in the trapFilterList array, then do one of the following:
    • Delete the filter object from the array, or
    • Set the value field to null.
  4. Save the file.
  5. Restart the MCE for the changes to take effect.
    ./deactivate.pl
    ./activate.pl

For additional details, examples, and validation rules, see the README file located in /opt/oracle/mce/cfg/trapfilter.