cancel
Showing results for 
Search instead for 
Did you mean: 

saprouter starting problem

sivakumar_kilari3
Active Contributor
0 Kudos

Hi All,

I configured saprouter in solman server(windows) iam unable start saprouter . I gave the follwoing command its not giving any output.

C:\saprouter\ntintel>saprouter -r -G routlog -S 3299 -K "p:CN=solman, OU=SAProut

er, O=SAP, C=DE"

trcfile dev_rout

logfile routlog

Regards

Siva

Accepted Solutions (0)

Answers (1)

Answers (1)

Former Member
0 Kudos

Hi,

Check dev_rout

regards,

kaushal

sivakumar_kilari3
Active Contributor
0 Kudos

Hi ,

Thanks for your reply,

When i am following command its giving diffrent output,

C:\saprouter\ntintel>saprouter -r -k "p:CN=solman,OU=0000731019, OU=SAProuter, O

=SAP, C=DE"

SAP Network Interface Router, Version 38.10

Compiled May 22 2007 00:31:59

start router : saprouter -r

stop router : saprouter -s

soft shutdown: saprouter -p

router info : saprouter -l (-L)

new routtab : saprouter -n

toggle trace : saprouter -t

cancel route : saprouter -c id

dump buffers : saprouter -d

flush " : saprouter -f

hide errInfo : saprouter -z

start router with third-party library: saprouter -a library

additional options

-R routtab : name of route-permission-file (default ./saprouttab)

-G logfile : name of log file (default no logging)

-T tracefile : name of trace file (default dev_rout)

-V tracelev : trace level to run with (default 1)

-H hostname : of running SAProuter (default localhost)

-S service : service-name / number (default 3299)

-P infopass : password for info requests

-C clients : maximum no of clients (default 800)

-Y servers : maximum no of servers to start (default 1)

-K [myname] : activate SNC; if given, use 'myname' as own sec-id

-A initstring: initialization options for third-party library

-D : switch DNS reverse lookup off

-E : append log- and trace-files to existing

-J filesize : maximum log file size in byte (default off)

-6 : IPv6 enabled

-Z : hide connect error information for clients

expert options

-B quelength : max. no. of queued packets per client (default 1)

-Q queuesize : max. total size for all queues (default 20000000 bytes)

-W waittime : timeout for blocking net-calls (default 5000 millisec)

-M min.max : portrange for outgoing connects, like -M 1.1023

-I address : address for outgoing connects, like -I 155.56.76.6

  1. this is a sample routtab : -----------------------------------------

D host1 host2 serviceX

D host3

P * * serviceX

P 155.56.. 155.56

P 155.57.1011xxxx.*

P host4 host5 * xxx

P host6 localhost 3299

P host7 host8 telnet

S host9

P0,* host10

KP sncname1 * *

KS * host11 *

KD "sncname "abc" * *

KT sncname3 host11 *

  1. deny routes from host1 to host2 serviceX

  2. deny all routes from host3

  3. permit routes from anywhere to any host using serviceX

  4. permit all routes from/to addresses matching 155.56

  5. permit ... with 3rd byte matching 1011xxxx

  6. permit routes from host4 to host5 if password xxx supplied

  7. permit information requests from host6

  8. permit native-protocol-routes to non-SAP-server telnet

  9. permit ... excluding native-protocol-routes (SAP-servers only)

  10. permit ... if number of preceding/succeeding hops (SAProuters) <= 0/*

  11. permit SNC-connection with partnerid = 'sncname1' to any host

  12. permit all SAP-SAP SNC-connections to host11

  13. deny all SNC-connections with partnerid = 'sncname "abc'

  14. open connects to host11 with SNC enabled and partnerid = 'sncname3'

  1. first match [host/sncname host service] is used

  2. permission is denied if no entry matches

  3. service wildcard (*) does not apply to native-protocol-routes

  4. --------------------------------------------------------------------

Regards

Siva

sivakumar_kilari3
Active Contributor
0 Kudos

Hi Kaushal,

Please check this

-


trc file: "dev_rout", trc level: 1, release: "700"

-


Wed Oct 22 12:45:08 2008

SAP Network Interface Router, Version 38.10

command line arg 0: saprouter

command line arg 1: -r

command line arg 2: -G

command line arg 3: routlog

command line arg 4: -S

command line arg 5: 3299

command line arg 6: -K

command line arg 7: p:CN=solman, OU=SAProuter, O=SAP, C=DE

SncInit(): Initializing Secure Network Communication (SNC)

PC with Windows NT (mt,ascii,SAP_UC/size_t/void* = 16/32/32)

SncInit(): Trying environment variable SNC_LIB as a

gssapi library name: "C:\saprouter\ntintel\sapcrypto.dll ".

File "C:\saprouter\ntintel\sapcrypto.dll " dynamically loaded as GSS-API v2 library.

The internal Adapter for the loaded GSS-API mechanism identifies as:

Internal SNC-Adapter (Rev 1.0) to SECUDE 5/GSS-API v2

main: pid = 3676, ppid = 0, port = 3299, parent port = 0 (0 = parent is not a saprouter)

reading routtab: './saprouttab'

Regards

Siva

Former Member
0 Kudos

HI,

According to dev_rout your saprouter is running without any error.

regards,

kaushal

sivakumar_kilari3
Active Contributor
0 Kudos

Hi,

How Can I know it is running or not.

Regards

Siva

sivakumar_kilari3
Active Contributor
0 Kudos

Hi Kaushal,

I am unable to executing oss1 transaction,

it is giving error

Unable connect sap Netmessage server

What is the problem ?

Regards

Siva

Former Member
0 Kudos

Hi,

Did you maintain technical settings fro OSS1 ?

after maintaining it

Please check if you are able to access RFC connection via t/c:sm59 -->

R3 support /ABAP --> SAPOSS --> RFC connection

if connection working is fine then your configuration is OK

also check

regards,

kaushal

sivakumar_kilari3
Active Contributor
0 Kudos

Kaushal,

t/c:sm59 -->

R3 support /ABAP --> SAPOSS --> RFC connection

This is fail

RFC connection technical settings.

Target host:OSS

Msg Server:/H/125.16.64.141/S/sapdp00/H/194.117.106.129/S/sapdp99/H/oss001

Group.EWA

Ipaddress: /H/125.16.64.141/S/sapdp00/H/194.117.106.129/S/sapdp99/H/oss001

Logon & security details

Client :001

user:OSS_RFC

Please help me . this is very urjent.

Regards

Siva

Former Member
0 Kudos

Hi,

Are you able to ping 125.16.64.141 from your host where saprouter is running?

125.16.64.141 is this IP of host where sap router is running?

regards,

kaushal

sivakumar_kilari3
Active Contributor
0 Kudos

Hi,

This is public ip of my saprouter system.

Regards

Siva

sivakumar_kilari3
Active Contributor
0 Kudos

Kaushal,

Public ip 125.16.64.141.

local ip :10.14.147.32

I configured saprouter in solman server.

Regards

Siva

Former Member
0 Kudos

HI,

If local IP is 10.14.147.32 then you need to assign this ip address to local saprouter ( i.e sap router at customer side) in OSS1 technical settings.

and also make sure you are configure saprouttab correctly according to your ip address in system landscape.

regards,

kaushal

sivakumar_kilari3
Active Contributor
0 Kudos

Kaushal,

I changed ip address saprouter at customer site

SAPOSS conneection test error

Logon Connection Error

Error Details Error when opening an RFC connection

Error Details ERROR: internal error

Error Details LOCATION: SAP-Server solman_SMS_00 on host solman (wp 0)

Error Details DETAIL: NiBufIIn: invalid data received

Error Details COMPONENT: NI (network interface)

Error Details COUNTER: 1778

Error Details MODULE: nibuf.cpp

Error Details LINE: 2858

Error Details RETURN CODE: -1

Error Details SUBRC: 0

Error Details RELEASE: 700

Error Details TIME: Wed Oct 22 16:54:13 2008

Error Details VERSION: 38

-


this is my saprouttab details

  1. Connection from SAP to local system for R/3 Support

P 194.117.106.129 125.16.64.141 3200

  1. Connection from SAP to local system for pcAnywhere, if applicable

#P 194.117.106.129 <IP-address> 5631

  1. Connection from SAP to local system for WTS, if applicable#

#P 194.117.106.129 <IP-address> 3389

  1. Connection from SAP to local system for SAPtelnet, if applicable#

#P 194.117.106.129 <IP-address> 23

  1. Access from your local network to SAP

KT "p:CN=sapserv1, OU=SAProuter, O=SAP, C=DE" 194.117.106.129 *

P * 194.117.106.129 3299

P 125.16.64.141 194.117.106.129 3299

  1. All other connections will be denied

D * * *

Thanks & Regards

Siva

sivakumar_kilari3
Active Contributor
0 Kudos

Hi,

Data at SAP side:

SAP VPN public IP address: 194.39.131.167

Type of VPN switch: CISCO IOS Router

SAP SAPRouter (sapserv1): 194.117.106.129

(SAP Subnet: 194.117.106.128 Netmask: 255.255.255.252)

Datas at Customer Side:

Public IP address of VPN switch: 125.16.64.141

Type of VPN switch :

Pre-Shared Key: see additional fax sent to +91-512-2355406

IP address of SAProuter : 125.16.64.141

Host name of SAProuter computer: solman

I got this from sap.

Is there any error my routtab file.

Pleaese advise.

Regards

Siva

sivakumar_kilari3
Active Contributor
0 Kudos

Hi ,

SAP VPN public IP address: 194.39.131.167

Type of VPN switch: CISCO IOS Router

SAP SAPRouter (sapserv1): 194.117.106.129

(SAP Subnet: 194.117.106.128 Netmask: 255.255.255.252)

I am unable to ping 194.39.131.167,194.117.106.128 and 194.117.106.128,

what is the problem.

Regards

Siva

sivakumar_kilari3
Active Contributor
0 Kudos

Hi All,

Please help me on this.

Regards

Siva

sivakumar_kilari3
Active Contributor
0 Kudos

Hi All,

I ran this command. saprouter -r -V 3 -K "p:<Distinguished name>"

I get the following message in a 'trace file'

-


trc file: "dev_rout", trc level: 3, release: "700"

-


Thu Oct 23 09:22:28 2008

NiHsLInit: alloc host/serv bufs (200/200 entries)

NiIInit: allocated nitab (811 at 02CA02C8)

NiIInit: host/serv bufs already initialized

NiPGetNodeAddrList: got 1 interface(s) from operating system

[0] IP-Address: 10.14.147.32

SAP Network Interface Router, Version 38.10

Compiled May 22 2007 00:31:59

command line arg 0: saprouter

command line arg 1: -r

command line arg 2: -V

command line arg 3: 3

command line arg 4: -K

command line arg 5: p:CN=solman, OU=0000731019, OU=SAProuter, O=SAP, C=DE

service : 3299

routtab : ./saprouttab

plug-in : no plug-in

-argument: 'no argument'

clients : 800

max servers : 1

quelength : 1

maxheap : 20000000

timeoutL : 5000

tracefile : dev_rout

logfile : no logging active

portrange : no portrange active

local address : default address

->> SncInit(prg=0, ini_fname=(NULL), &sec_avail=0157F6BF)

SncInit(): Initializing Secure Network Communication (SNC)

PC with Windows NT (mt,ascii,SAP_UC/size_t/void* = 16/32/32)

SncInit(): Trying environment variable SNC_LIB as a

gssapi library name: "C:\saprouter\ntintel\sapcrypto.dll ".

load shared library (C:\saprouter\ntintel\sapcrypto.dll ), hdl 0

using "C:\saprouter\ntintel\sapcrypto.dll"

DlLoadFunc: GetProcAddress(sapsnc_init_adapter) Error 127

Error 127 = "The specified procedure could not be found."

load shared func (gss_acquire_cred) from C:\saprouter\ntintel\sapcrypto.dll

load shared func (gss_release_cred) from C:\saprouter\ntintel\sapcrypto.dll

load shared func (gss_init_sec_context) from C:\saprouter\ntintel\sapcrypto.dll

load shared func (gss_accept_sec_context) from C:\saprouter\ntintel\sapcrypto.dll

load shared func (gss_process_context_token) from C:\saprouter\ntintel\sapcrypto.dll

load shared func (gss_delete_sec_context) from C:\saprouter\ntintel\sapcrypto.dll

load shared func (gss_context_time) from C:\saprouter\ntintel\sapcrypto.dll

load shared func (gss_get_mic) from C:\saprouter\ntintel\sapcrypto.dll

load shared func (gss_verify_mic) from C:\saprouter\ntintel\sapcrypto.dll

load shared func (gss_wrap) from C:\saprouter\ntintel\sapcrypto.dll

load shared func (gss_unwrap) from C:\saprouter\ntintel\sapcrypto.dll

load shared func (gss_display_status) from C:\saprouter\ntintel\sapcrypto.dll

load shared func (gss_indicate_mechs) from C:\saprouter\ntintel\sapcrypto.dll

load shared func (gss_compare_name) from C:\saprouter\ntintel\sapcrypto.dll

load shared func (gss_display_name) from C:\saprouter\ntintel\sapcrypto.dll

load shared func (gss_import_name) from C:\saprouter\ntintel\sapcrypto.dll

load shared func (gss_release_name) from C:\saprouter\ntintel\sapcrypto.dll

load shared func (gss_release_buffer) from C:\saprouter\ntintel\sapcrypto.dll

load shared func (gss_release_oid_set) from C:\saprouter\ntintel\sapcrypto.dll

load shared func (gss_inquire_cred) from C:\saprouter\ntintel\sapcrypto.dll

load shared func (gss_add_cred) from C:\saprouter\ntintel\sapcrypto.dll

load shared func (gss_inquire_cred_by_mech) from C:\saprouter\ntintel\sapcrypto.dll

load shared func (gss_inquire_context) from C:\saprouter\ntintel\sapcrypto.dll

load shared func (gss_wrap_size_limit) from C:\saprouter\ntintel\sapcrypto.dll

load shared func (gss_export_sec_context) from C:\saprouter\ntintel\sapcrypto.dll

load shared func (gss_import_sec_context) from C:\saprouter\ntintel\sapcrypto.dll

load shared func (gss_create_empty_oid_set) from C:\saprouter\ntintel\sapcrypto.dll

load shared func (gss_add_oid_set_member) from C:\saprouter\ntintel\sapcrypto.dll

load shared func (gss_test_oid_set_member) from C:\saprouter\ntintel\sapcrypto.dll

load shared func (gss_inquire_names_for_mech) from C:\saprouter\ntintel\sapcrypto.dll

load shared func (gss_inquire_mechs_for_name) from C:\saprouter\ntintel\sapcrypto.dll

load shared func (gss_canonicalize_name) from C:\saprouter\ntintel\sapcrypto.dll

load shared func (gss_export_name) from C:\saprouter\ntintel\sapcrypto.dll

load shared func (gss_duplicate_name) from C:\saprouter\ntintel\sapcrypto.dll

File "C:\saprouter\ntintel\sapcrypto.dll " dynamically loaded as GSS-API v2 library.

The internal Adapter for the loaded GSS-API mechanism identifies as:

Internal SNC-Adapter (Rev 1.0) to SECUDE 5/GSS-API v2

<<- SncPDLInit()==SAP_O_K

<<- SncInit()==SAP_O_K

sec_avail = "true"

->> SncSetMyName(snc_hdl=00000000, myname="p:CN=solman, OU=0000731019, OU=SAProuter, O=SAP, C=DE")

<<- SncSetMyName()==SAP_O_K

in: myname = "p:CN=solman, OU=0000731019, OU=SAProuter, O=SAP, C=DE"

NiBufISetParam: set max heap to 20000000

NiSetParamEx: switch NIP_CONNLOCAL off (not supported by platform)

NiIMyHostName: hostname = 'solman'

main: pid = 1032, ppid = 0, port = 3299, parent port = 0 (0 = parent is not a saprouter)

NiICreateHandle: hdl 0 state NI_INITIAL

NiIInitSocket: set default settings for new hdl 0 / sock 876 (I4; ST)

NiITraceByteOrder: CPU byte order: little endian, reverse network, low val .. high val

NiIBind: hdl 0 bound to 3299 (IP only)

NiIBlockMode: set blockmode for hdl 0 FALSE

NiIListen: state of hdl 0 NI_LISTEN

NiIListen: listen for client requests on hdl 0

NiSelICreateSet: new set0

SiSelNInit: allocate 134560 bytes for FI (811)

NiSelIInit: size of set0 is 811

SiSelNSet: sock 876 added to set pos 0

NiSelIAddMsg: added hdl 0 to set0

SiSelNSet: set events of sock 876 to: rp-

reading routtab: './saprouttab'

NiStrToAddrMask: '194.117.106.129' -> 194.117.106.129 [ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff]

NiStrToAddrMask: '10.14.147.32' -> 10.14.147.32 [ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff]

NiIGetServNo: servicename '3200' = port 0C.80/3200

NiStrToAddrMask: '194.117.106.129' -> 194.117.106.129 [ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff]

NiIGetServNo: servicename '3299' = port 0C.E3/3299

NiStrToAddrMask: '10.14.147.32' -> 10.14.147.32 [ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff]

NiStrToAddrMask: '194.117.106.129' -> 194.117.106.129 [ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff]

NiIGetServNo: servicename '3299' = port 0C.E3/3299

contents of routtab ('./saprouttab', 4 entries):

P, 194.117.106.129 ffff:ffff:ffff: 10.14.147.32 ffff:ffff:ffff: 3200 *

P, 0:0:0:0:0:0:0:0 0:0:0:0:0:0:0:0 194.117.106.129 ffff:ffff:ffff: 3299 *

P, 10.14.147.32 ffff:ffff:ffff: 194.117.106.129 ffff:ffff:ffff: 3299 *

D, 0:0:0:0:0:0:0:0 0:0:0:0:0:0:0:0 0:0:0:0:0:0:0:0 0:0:0:0:0:0:0:0 * *

              • NI-ROUTER LOOP ********

SiSelNSelect: start select (timeout=-1)

Regards

Siva

sivakumar_kilari3
Active Contributor
0 Kudos

Problem solved. I was contacp sap india.

Thanks your inputs

Former Member
0 Kudos

how did this solve was it a network issue or any other issue.

Regards

jith

Former Member
0 Kudos

Hi RD

There will be SAP side SAP firewall and SAP router under which they need to add the routtab entry and allow the external servers trying to talk to the SAP server.

should have enabled and cleared other errors

Regards

Raj