Skip to main content

How to resolve ORA-24247: Network Access Denied by ACL

🌐 ORA-24247: Network Access Denied by ACL in Oracle – Explained & Resolved

When working with Oracle debugging features like DBMS_DEBUG_JDWP, you might encounter the following error:

ORA-24247: Network access denied by access control list (ACL)
ORA-06512: at "SYS.DBMS_DEBUG_JDWP", line 68
ORA-06512: at line 1

This blog will walk you through the cause and step-by-step resolution of this issue using Oracle Access Control Lists (ACLs).


❓ What Is Causing This Error?

  • ACL Restriction: The database user is trying to initiate a network connection (e.g., for debugging), but no ACL grants access to the specified IP and port.
  • Missing Privileges: The user may lack the connect or resolve privilege in the ACL linked to that host/port.

Example Failing Statement:

CALL DBMS_DEBUG_JDWP.CONNECT_TCP('10.1.1.1', '62918');

✅ Step-by-Step Solution

🔧 1. Create a New ACL

BEGIN
  DBMS_NETWORK_ACL_ADMIN.CREATE_ACL(
    acl         => 'debug_acl.xml',
    description => 'ACL for debugging',
    principal   => 'TEST',
    is_grant    => TRUE,
    privilege   => 'connect'
  );
END;
/

🔐 2. (Optional) Add PUBLIC Privilege

BEGIN
  DBMS_NETWORK_ACL_ADMIN.ADD_PRIVILEGE(
    acl         => 'debug_acl.xml',
    principal   => 'PUBLIC',
    is_grant    => TRUE,
    privilege   => 'connect'
  );
END;
/

Note: This step is optional and should be used with caution.

🌍 3. Assign the ACL to the Host and Port

BEGIN
  DBMS_NETWORK_ACL_ADMIN.ASSIGN_ACL(
    acl         => 'debug_acl.xml',
    host        => '10.1.1.1',
    lower_port  => 62918,
    upper_port  => 62918
  );
END;
/

🔓 4. Add Resolve Privilege

BEGIN
  DBMS_NETWORK_ACL_ADMIN.ADD_PRIVILEGE(
    acl        => 'debug_acl.xml',
    principal  => 'TEST',
    is_grant   => TRUE,
    privilege  => 'resolve'
  );
END;
/

💾 5. Commit the Changes

COMMIT;

🔍 Verifying ACL Configuration

📄 View Assigned ACLs:

SELECT acl, host, lower_port, upper_port
FROM dba_network_acls;

👤 View ACL Privileges:

SELECT acl, principal, privilege, is_grant
FROM dba_network_acl_privileges;

🎯 Final Result

With these ACL entries in place, the user TEST can now successfully call:

CALL DBMS_DEBUG_JDWP.CONNECT_TCP('10.1.1.1', '62918');

No more ORA-24247 errors! 🎉


🛡️ Best Practices

  • Grant ACL privileges only to required users.
  • Be cautious with PUBLIC access.
  • Use specific host and port ranges instead of wildcards.
  • Review ACL entries regularly for security audits.

Got questions or need help automating ACL configuration with a script or Ansible? Drop a comment or reach out! 🚀

Comments

Popular posts from this blog

🚀 Automating Oracle Database Patching with Ansible: A Complete Guide

Oracle database patching has long been the bane of DBAs everywhere. It's a critical task that requires precision, expertise, and often results in extended maintenance windows. What if I told you that you could automate this entire process, reducing both risk and downtime while ensuring consistency across your Oracle estate? 💡 In this comprehensive guide, I'll walk you through a production-ready Ansible playbook that completely automates Oracle patch application using OPatch. Whether you're managing a single Oracle instance or hundreds of databases across your enterprise, this solution will transform your patch management strategy! 🎯 🔥 The Challenge: Why Oracle Patching is Complex Before diving into the solution, let's understand why Oracle patching is so challenging: 🔗 Multiple dependencies : OPatch versions, Oracle Home configurations, running processes ⚠️ Risk of corruption : Incorrect patch application can render databases unusable ⏰ Downtime requirements : Da...

Complete Guide to PostgreSQL 18 Source Installation with Performance Optimization

PostgreSQL 18 brings powerful new features and performance improvements that make it an excellent choice for modern database workloads. In this comprehensive guide, I'll walk you through installing PostgreSQL 18 from source code while implementing a strategic disk layout that maximizes performance. Why Install from Source? While package managers offer convenience, building PostgreSQL from source gives you complete control over configuration and optimization options. This flexibility allows you to tailor the database precisely to your hardware and workload requirements. Prerequisites Before we begin, ensure you're working with a RHEL, CentOS, or Fedora-based system. We'll be installing several development tools and libraries needed for compilation. Installation Process 1. Download PostgreSQL 18 Source Code First, grab the latest PostgreSQL 18 source tarball: wget https://ftp.postgresql.org/pub/source/v18.0/postgresql-18.0.tar.gz 2. Install Required Dependencies Install all n...

⚡ Automating Oracle 19c Database Patching on Windows Server with PowerShell

Applying Oracle patches on Windows often feels repetitive and error-prone — stopping services, updating OPatch, applying patches, running datapatch , and restarting services. To save time ⏱ and reduce mistakes ⚠, I created a PowerShell automation script that performs the patching process end-to-end 🚀. 🔹 Why Automate Oracle Patching? ⏱ Save time by automating repetitive steps ⚙ Avoid manual errors during patching 📜 Maintain logs for auditing and troubleshooting 🛡 Ensure consistent, reliable patching 🔹 Full PowerShell Script # --- CONFIGURATION --- $oracleHome = "c:\users\administrator\downloads\v982656-01" # Change if this is not your actual Oracle Home! $patchDir = "C:\Users\Administrator\Downloads\p37962957_190000_MSWIN-x86-64\37962957" #update the Patchfile directory $opatchDir = "$oracleHome\OPatch" $opatchZip = "C:\Users\Administrator\Downloads\p6880880_190000_MSWIN-x86-64.zip" #Based on your setup update Opatch di...