cancel
Showing results for 
Search instead for 
Did you mean: 

SAProuter with SNC over the Internet for SAP support

Former Member
0 Kudos

Hi All,

We would like to replace our ISDN dial up connection for OSS and I have some questions regarding setting up SAProuter and SNC.

I've got Volker's very good document from http://www.easymarketplace.de/snc-iseries-setup.php but my questions are more to do with the setup outside of SAP.

In the Technical Specification document under https://service.sap.com/saprouter-sncdoc it states that the SAProuter machine should be in the DMZ with a non-private ip address.

<u><b>Question</b></u>: Can the SAProuter be on the internal network with a private IP address but accessed by via the Public address of our firewall and proxied through?

In Note 84243 it states that the following ports must be accessible.

for OSS access, a TCP link to the SAProuter must be allowed on sapservX: (in Cisco Notation, similar for other routers or firewalls)

permit tcp host host eq 3299

permit tcp host host gt 1023 established

for the remote link from SAP to the customer, a TCP link and a ping must be allowed from sapservX to the SAProuter at the customer site:

permit tcp host host eq 3299

permit tcp host host gt 1023 established

permit icmp host host eq echo echo-reply

permit icmp host host eq echo-reply echo

<u><b>Question</b></u>: Must all these ports be opened? Elsewhere Volker has stated only one port is required to be opened through the firewall.

<u><b>Question</b></u>: Exactly how secure is this connection? What measures have others taken to protect the connection.

Sorry for the long post and the not strictly Basis questions, but I know there is a fountain knowledge out there.

Regards

Steve

Accepted Solutions (0)

Answers (3)

Answers (3)

Former Member
0 Kudos

Thanks both. That's what I figured. The SAP documentation makes it look overly complicated, and since I hadn't read about a general wailing and gnashing of teeth regarding the setup, I thought it must be easier.

I'll give it a go.

Cheers

Steve

Former Member
0 Kudos

Hi Stephen,

Question: Can the SAProuter be on the internal network with a private IP address but accessed by via the Public address of our firewall and proxied through?

yes, no problem, just a port forwarding for this one port 3299 for insite and NAT for outsite is required!

Question: Must all these ports be opened? Elsewhere Volker has stated only one port is required to be opened through the firewall.

ONLY port 3299 - I did several setups this way )

Question: Exactly how secure is this connection? What measures have others taken to protect the connection.

As save as a 128 Bit certificate is - by now I didn't hear on breaking that => it is safe with state of the art )

(I would imagine VPN is 128 Bit "only" as well)

=> really go for that ....

Regards

Volker Gueldenpfennig, consolut.gmbh

http://www.consolut.de - http://www.4soi.de - http://www.easymarketplace.de

Former Member
0 Kudos

Hello Stephen,

Based on what I know...

Question: Can the SAProuter be on the internal network with a private IP address but accessed by via the Public address of our firewall and proxied through?

I think you are talking about IP alias, or some term like that... Yes, it would work.

Question: Must all these ports be opened? Elsewhere Volker has stated only one port is required to be opened through the firewall.

3299 is the primary port. Ping would help the troubleshooting when needed.

As you specify the IP addresses of sapservX in "permit", only traffic from SAP is allowed. So even all the ports mentioned are open, you should be able to pass the security audit.

Question: Exactly how secure is this connection? What measures have others taken to protect the connection.

Either VPN or SNC should be good enough if correctly configured.

Best regards,

Victor