Network Settings

Objective

After completing this lesson, you will be able to explain which network settings need to be configured for the connection between the source system and the SAP Signavio Process Insights tenant.

Network Setting in General

Banner to show Step 3 of Administrators Collaboration

Administrators Collaboration - Sequence - Step 3

The graphic shows three persons in the upper part. Three people represent the different administrators for the source systems, SAP Signavio Process Insights, and BTP. In the lower part, the systems or Platforms visualized and their relationships represented with arrows. In addition, the 5 steps of collaboration between these persons are shown on a timeline. These steps need to be performed twice for test and production.

In this section, step 3 is considered in the interaction of administrators.

Banner for Configur Network SettingsThe banner indicates that this section is aimed at the administrator of the source system.

This section of the course is relevant for: SAP Source System Administrators

For being able to execute the following steps you need some information from SAP BTP. When your user has been added to the user step of the booster, you should be authorized. If you are not able to access the information with your own user please involve the SAP BTP Administrator for getting the relevant details.

You will collect and need the following information for the network settings:

  • SAP BTP Sub-accont "subdomain"
  • SAP BTP Data Center "region ID"
  • SAP BTP, Cloud Foundry IP Addresses
  • HTTPs connection, Proxy (host and port)

Configure the network

You need to ensure your network settings permit communication required for the SAP Signavio Process Insights solution. Potentially you need to contact another IT specialist from your organisation. You must ensure that your company's network settings permit outbound communications to the internet through port 443 (HTTPS) to the domains for the solution. Also ensure that you permits the URLs and IP addresses required by the SAP Signavio Process Insights solution for communication.

Let's start with the first 3 settings:

(A) URLs to Be Permitted

You need to permit communication with the following URLs:

  • Application base URL

    This is the uri property obtained by your SAP Business Technology Platform (SAP BTP) administrator from the service key created by running the booster to subscribe to the application. For information about how to get the service key details, see Getting Your Service Key Details (SAP On-Premise Systems).

    bpi-pia-core-api.cfapps."region ID".hana.ondemand.com

  • Authentication URL

    This is your tenant-specific authentication URL that matches the url property also obtained by your SAP BTP administrator from the service key that they created:

    "subdomain".authentication."region ID".hana.ondemand.com

    The subdomain is the subdomain of the subaccount used to create a subscription to the application in the SAP BTP cockpit. The region ID is the region of the data center of the subaccount.

Hint

SAP Signavio Process Insights is a rapidly evolving cloud software. Please check the latest version of the Documentation

The picture shows the BTP Cockpit - Subaccount section Instances where the key is displayed in a seperate window. Two lines of this file are relevant for this section.

Hint

Find a list of Data Centers and Regions available in the documentation.

There is one exception: If you're running SAP Signavio Process Insights in the AWS Europe (Frankfurt) region with region ID eu10, please specify eu10-004 as the region ID.

Now you're on

The banner indicates that tasks need to be completed.
  • Permit the required Application base URL - bpi-pia-core-api.cfapps."region ID".hana.ondemand.com
  • Permit the required Authentication URL - "subdomain".authentication."region ID".hana.ondemand.com
next chapter

(B) IP Addresses to Be Permitted

Your network must allow the required IPs for the SAP BTP, Cloud Foundry environment.

For information about which IPs are required, see Regions and API Endpoints Available for the Cloud Foundry Environment in the SAP BTP documentation. The information in the LB IPs (ingress, for incoming requests) column indicates which IPs are required depending on your data center.

Hint

SAP Signavio Process Insights is a rapidly evolving cloud software. Please check the latest version of the Documentation

The banner indicates that tasks need to be completed.
  • Check the documentation about which IPs are required, see Regions and API Endpoints Available for the Cloud Foundry Environment in the SAP BTP documentation. The information in the LB IPs ( ingress, for incoming requests) column indicates which IPs are required depending on your data center.

  • Permit the required IP Addresses
next chapter

(C) Proxy (host and port)

Configure proxy settings

The connection between a managed system and SAP Signavio Process Insights is established using an HTTPS connection. If your organization uses proxies, the proxies must be maintained when establishing the connection or directly in the system connection using transaction SM59 (Configuration of RFC Connections).

Hint

SAP Signavio Process Insights is a rapidly evolving cloud software. Please check the latest version of the Documentation

The banner indicates that tasks need to be completed.
  • You know whether your organization uses a proxy and have obtained the details required (host and port) from your organization's IT department or specialist. If your proxy uses authentication and you're using ST-PI 7.40 SP16, ensure you've installed the corresponding SAP Note 3104662 . This SAP Note is required to ensure that proxies with authentication are supported by the SAP Cloud ALM functionality in your ST-PI plug-in. The functionality is used to connect your SAP ECC 6.0 or SAP S/4HANA source system to the cloud tenant.
  • You need this information for setting up the connection later.
next chapter

Network Settings in SAP Source System (on-premise)

SAP Source System Steps of Configure Network Settings

Banner for Configure Network Setting in SAP Source SystemThe banner indicates that this section is aimed at the administrator of the source system.

This section of the course is relevant for: SAP Source System Administrators

(D) Import the SAP Cloud ALM certificate

SAP Signavio Process Insights uses the SAP Cloud ALM functionality included in the ST-PI plug-in to let you connect a managed system to your cloud tenant. You must install and trust the required certificate in all systems you connect.

For more information, see Installing the Required Certificates.

Hint

Depending on the source system you're connecting, you trust and install the required certificates in different systems:

  • If you're connecting an SAP on-premise system directly to SAP Signavio Process Insights, you install and trust the certificates directly in the source system.
  • If you're connecting an SAP on-premise system to SAP Signavio Process Insights using an intermediate system, you install and trust the certificates in the intermediate system only.

Hint

Please remember to make these settings in all systems and transport the changes from the DEV to the QAS and PRD system.

Now you're on

The banner indicates that tasks need to be completed.

In any SAP on-premise systems that you connect, you must install and trust all the required certificates as outlined under Setup STRUST in the information for SAP Cloud ALM on SAP Support Portal.

Make sure you install and trust the following root certificates:

  • DigiCertGlobalRootCA

    This root certificate is used to sign existing certificates. It will soon be replaced by DigiCertGlobalRootG2 for signing new certificates.

  • DigiCertGlobalRootG2

    This root certificate is scheduled to replace DigiCertGlobalRootCA in 2023 still. Both certificates can co-exists in your systems. Please don't delete the old certificate (DigiCertGlobalRootCA) before its expiry date.

  • DigiCertRSA4096RootG5

    This root certificate prepares your trust store for future use where increased key length is required.

Hint

Please remember to make these settings in all systems and transport the changes from the DEV to the QAS and PRD system.
next chapter

(E) HTTPS Parameter / Set SSL configuration parameters

Server Name Indication (SNI) must be enabled for client connections.

Hint

SAP Signavio Process Insights is a rapidly evolving cloud software. Please check the latest version of the Documentation

Now you're on

The banner indicates that tasks need to be completed.
  • Check that the profile parameter icm/HTTPS/client_sni_enabled is set to TRUE in your managed system. You can check this value using transaction RZ11 and
  • change it using transaction RZ10. In transaction RZ10, you select the relevant profile and change the value from FALSE to TRUE. See also SAP Note 510007   (Additional considerations for setting up SSL on Application Server ABAP).

Hint

Depending on the source system you're connecting, you set the profile parameter in different systems:

  • If you're connecting an SAP on-premise system directly to SAP Signavio Process Insights, you do the profile parameter settings in the source system.
  • If you're connecting an SAP on-premise system to SAP Signavio Process Insights using an intermediate system, you do the profile parameter settings in the intermediate system only.

Hint

Please remember to make these settings in all systems and transport the changes from the DEV to the QAS and PRD system.

Log in to track your progress & complete quizzes