APPENDIX 1: System Config Manager Parameters
Parameter Name | Description | Sample Parameter Value | Restart Required | Configuration Location |
|---|---|---|---|---|
sql.proxy.bind.port | This parameter defines the port range for auto assigning sql.proxy.bind.port parameter | 1025-2000 | No | System config manager |
sql.proxy.node.auto.register.enabled | Enables automatic registration of Oracle RAC nodes in SQL proxy | True | No | System config manager |
dam.ddm.mfa.enabled | Enables Multi-Factor Authentication for SQL Proxy connections. | True | No | System config manager |
dam.ddm.mfa.delimiter | Defines the delimiter separating the MFA code from the username. | # | No | System config manager |
sql.proxy.metadata.sync.period | Sets the interval (in ms) for synchronizing database metadata. | 30000 | Yes | /pam/sql/config/application.properties (Linux) |
dam.ddm.server.clone.enforce.user.role | Forces read-only access for users connecting via the cloned port. | readonly | No | Device Properties |
dam.ddm.server.enforce.user.groups | Defines user groups required to connect via the main SQL proxy port. | UG1, UG2 | No | Device Group Properties |
dam.ddm.server.clone.bind-port | Specifies the port for read-only SQL Proxy access. | 1000-4000 | No | Device Properties |
dam.ddm.server.clone.enforce.user.groups | Defines user groups required to connect via the read-only port. | UG3,UG4 | No | Device Group Properties |
sql.proxy.user.swap.enabled | Enables user identity swapping for SSO in SQL Proxy connections. | True | No | System Config manager |
aioc.second.password.ttl | Defines TTL for the second password in SSO (in days). | 30 | yes | System Config manager |
sdd.thread.count.default | Sets the default number of parallel connections for sensitive data discovery. | 10 | no | System config manager |
dam.ddm.buffer.overflow.attack.protection | Turns on the proxy’s buffer-overflow guard. When enabled, every incoming SQL packet is measured and—if it exceeds the size limit below—immediately dropped and logged. | True | yes | System config manager |
dam.ddm.buffer.overflow.limit | Maximum statement size (bytes). Queries larger than this are blocked. Choose a value that covers normal traffic (e.g., 1048576 = 1 MiB). | 1048576 (1 MiB) | yes | System config manager |
dam.ddm.connection.rate.limit.per.client.ip | Maximum allowed number of concurrent connection attempts per client IP. | 20 | Yes | System Config Manager |
dam.ddm.packet.client.rate.limit.per.database | Maximum allowed number of client packets (queries, pings, etc.) per database within the session period. | 20 | Yes | System Config Manager |
dam.ddm.packet.client.rate.limit.per.user | Maximum allowed number of client packets generated by an individual user. | 20 | Yes | System Config Manager |
dam.ddm.dos.attack.protection | Activates DoS / query-flood detection and throttling. Uses the two rate-limit thresholds that follow. | True | yes | System config manager |
dam.ddm.query.rate.limit.from.single.ip | Per-client threshold—max. queries per second allowed from one source IP before it is temporarily black-listed. | 100 | yes | System config manager |
dam.ddm.query.rate.limit.from.all.network | Global threshold—aggregate queries per second across the proxy. Exceeding it rejects new sessions until the rate falls. | 5000 | yes | System config manager |
sql.proxy.oracle.local.bind.port.tenant_aioc | This parameter defines port number of Oracle devices. All Oracle database connections are made through this port. For multitenant environments, the tenant’s name should be entered instead of the aioc. | 5000 | NO | System config manager |
device.database.source | This parameter defines the external device database IP addresses. Multiple values must be separated by “;”. The parameter is used to add/discover devices from external device databases. | E.g: 10.10.10.10;20.20.20.20 | NO | |
device.database.url_n | JDBC URL address for database connection. The parameter is used to add/discover devices from external device databases. | E.g: device.database.url_0 = jdbc:postgresql://10.10.10.10:5432/databasename | YES | |
device.database.user_n | External database username. The parameter is used to add/discover devices from external device databases. | E.g.: DB_1 | YES | |
device.database.password_n | External database password. The parameter is used to add/discover devices from external device databases. | must be set as "yes" | YES | |
device.database.sql_n | SQL Query to import devices. IP address, hostname, element type specifier, and one of the tag values are mandatory. The parameter is used to add/discover devices from external device databases. | E.g: device.database.sql_0 = SELECT "dynName" AS IP_ADDRESS, server AS HOSTNAME, os AS ELEMENT_TYPE_SPECIFIER , id AS PORT, os as TAG_OS, site as TAG_SITE FROM devicedatabase | YES | |
device.database.driver_n | Database driver for external database connection. The parameter is used to add/discover devices from external device databases. | E.g: device.database.driver_0 = org.postgresql.Driverdev | YES | |
sdd.query.oracle.column.excluded_types | Defines excluded column data types for Sensitive Data Discovery in Oracle | CLOB;BLOB;NCLOB;BFILE | NO | system.config.manager |
sdd.query.postgresql.column.excluded_types | Defines excluded column data types for Sensitive Data Discovery in PostgreSQL | BYTEA | NO | system.config.manager |
sdd.query.teradata.column.excluded_types | Defines excluded column data types for Sensitive Data Discovery in Teradata | CLOB;BLOB | NO | system.config.manager |
sdd.query.sqlserver.column.excluded_types | Defines excluded column data types for Sensitive Data Discovery in SQL Server | IMAGE;TEXT;NTEXT;VARBINARY(MAX) | NO | system.config.manager |
sdd.query.mysql.column.excluded_types | _types Defines excluded column data types for Sensitive Data Discovery in MySQL | BLOB;TEXT;MEDIUMBLOB;LONGBLOB | NO | system.config.manager |
sql.proxy.masking.enabled | Enables masking; true adds performance cost, false disables. | True | NO | system.config.manager |
block.procedural.sensitive.queries | Enables or disables blocking of procedural sensitive queries; set to false to allow connections from tools such as TOAD. | False | NO | system.config.manager |
dam.ddm.metadata.connection.timeout | DAM/DDM – SQL Proxy timeout duration in millisecondsMust be increased for dealing with databases with a high number of schemas/tables/functions/processes (metadata) in DDM modules like SQL Proxy in order to avoid timeouts. | 5000 (default value) | NO | System Config Manager |
dam.portal.web.client.timeout.seconds | Web Client timeout duration in seconds for DAM. Must be increased for dealing with large databases in modules like DAM Object Explorer in order to avoid timeouts. | 60 (default value) | NO | System Config Manager |