OSS Configuring VPN
OSS Configuring VPN
OSS Configuring VPN
Introduction
SAP has embarked on a project to enable its customers to establish secure connections to SAP over
the Internet for support purposes. Currently, SAP offers two alternative ways to connect to the
Support Network over the Internet:
SAP has implemented a functional subset of the Remote Customer Support Network services in an
Internet DMZ (demilitarized zone) in SAP AG, Walldorf. With this infrastructure in place, the suite
of Remote Customer Support Network service offerings is accessible over the Internet.
In this project Internet VPN was selected over SNC for the following reason
VPN using IPsec is industry standard and have better encryption
FTP is not possible with SNC.
Requirement
• Internet connection: recommended
minimum bandwidth = 64 kbps
• SAProuter machine
• Official IP address (static) for the SAProuter host.
• SAProuter installation package
• SAP SNC libraries and executables.
These may be downloaded from the SAP Service Marketplace.
• A Demilitarized Zone at the customer site with a minimal setup as described in the networking
section of the SAP Security Guide, Parts 1-3 available in the Service Marketplace at:
http://service.sap.com/SYSTEMMANAGEMENT Choose: Security > Technical Track
> SAP Security Guide.
More information on SNC connections is also available in the SAP Service Marketplace.
• Since the host running the SAProuter software is a full computer with operating system, the
security at the operating system level must be hardened in order to minimise the risk of the
machine being hacked from the Internet. One recommendation will be for example to run a C2
security level compliant operating system. SAP takes no liability if the security of the
company’s network is compromised.
• Other networking equipment (routers and hubs) needed to form the network at the customer’s
premises (see Figure 1).