14.5 Access Control
Restrict network access with GRANT_REMOTE_ACCESS, BIND_IP_ADDRESS, and OS or cloud
firewalls together. Check current values as follows.
SELECT NAME, VALUE
FROM V$PROPERTY
WHERE NAME IN ('GRANT_REMOTE_ACCESS', 'BIND_IP_ADDRESS');Listener settings take effect at server startup. Do not assume a running listener automatically
rebinds. Change machbase.conf, then follow the approved restart procedure.
Configure remote access
GRANT_REMOTE_ACCESS controls whether remote clients can connect.
# Allow remote access
GRANT_REMOTE_ACCESS = 1
# Block remote access
GRANT_REMOTE_ACCESS = 0Before changing the value, check:
- Connection origins for application, monitoring, and backup clients.
- How to retain local administrative access.
- The procedure for testing remote and emergency access after restart.
Configure a firewall allowlist alongside GRANT_REMOTE_ACCESS=1 so enabling remote access
does not admit every remote address.
BIND_IP_ADDRESS and network exposure
BIND_IP_ADDRESS specifies the address for the IPv4 listener.
# All IPv4 interfaces
BIND_IP_ADDRESS = 0.0.0.0
# Local IPv4 interface
BIND_IP_ADDRESS = 127.0.0.1
# Specified internal IPv4 interface
BIND_IP_ADDRESS = 10.0.0.5An address that does not exist on the server can prevent startup. Check current interface addresses before changing the setting. After restart, use OS tools to verify the actual listening address and port.
If 0.0.0.0 is required, restrict allowed source addresses and ports in the firewall or
security group. Firewall commands depend on the deployed OS and network policy; do not
blindly apply fixed commands from this manual.