Oracle Database initial setup
For initial load, see Oracle Database initial load.
For continuous real-time replication using Oracle Reader or OJet, significant setup is required. See Configuring Oracle to use Oracle Reader.
For continuous incremental replication using Incremental Batch Reader, see Oracle Database continuous incremental replication.
The following discussions of networking, security, and Forwarding Agent setup apply to both initial load and either approach to continuous replication.
Networking setup
The following applies to both initial load and any approach to continuous replication.
You need to establish proper network connectivity between your Striim environment and the Oracle database. This involves configuring network access, firewall rules, and connection parameters to ensure reliable communication.
Ensure that the Striim server can connect to your Oracle database on the correct port (typically 1521). If your Oracle database is behind a firewall, you need to configure the necessary firewall rules to allow inbound connections from the Striim server. For cloud deployments, such as Amazon RDS for Oracle, you need to configure security groups to allow access from your Striim instance.
Also consider network latency and bandwidth requirements, especially for high-volume CDC scenarios. For optimal performance, minimize the network latency between Striim and Oracle. If you're using Oracle RAC, you need to configure proper load balancing and failover settings in your connection strings.
For secure connections, you can configure SSL/TLS encryption between Striim and Oracle. This requires setting up SSL certificates and configuring both Oracle and Striim to use encrypted connections. You should also consider using Oracle Native Network Encryption for an additional layer of security.
Security
Security configuration for Oracle integration involves multiple layers, including authentication, authorization, network security, and data protection measures.
You must implement proper authentication mechanisms between Striim and Oracle. This includes creating dedicated database users with minimal required privileges following the principle of least privilege. You should avoid using administrative accounts and instead create specific users for Striim operations with only the necessary permissions for the tables and operations required.
For enhanced security, you can implement SSL/TLS encryption for all communication between Striim and Oracle. This protects data in transit, ensuring that credentials and sensitive data are not transmitted in clear text. You should also consider implementing Oracle Advanced Security features, such as Transparent Data Encryption (TDE), for data-at-rest protection.
Network security considerations include configuring Oracle Net Services with appropriate security settings, implementing proper firewall rules, and using Oracle Connection Manager for additional connection security and monitoring. You should also consider implementing Oracle Database Vault for additional access controls and Oracle Audit Vault for comprehensive auditing of database access.
You should implement access control at multiple levels, including database-level permissions, schema-level access controls, and table-level privileges. You should regularly review and audit the permissions granted to Striim users and implement proper password policies and rotation procedures for service accounts.