Quantcast
Channel: SCN: Message List - Security
Viewing all articles
Browse latest Browse all 5338

Re: Gateway Security: reginfo, secinfo, gw/acl_mode - how to set?

$
0
0

Hi Julia,

 

This complaint in the EWA is in my opinion not correct.

 

See SAP Note 1480644. The same is achieved by setting the gw/no_reg_conn_info to a value greater than 1 and you should do that anyway. It forces you to have your own correct files in place as the local and internal defaults are insufficient.

 

Ideal is first create full access files. Then switch the gw/no_reg_conn_info to an acceptable level for you but at least to 1, then use the gw/sim_mode to simulate failures for a while and maintain the files. Then consolidate all files from the same network zone into 1 set of files and aggregate it and relax the constraints for TP programs which are acceptable and not a security threat. Park those files on a central server which SAP can only read from and locally change the gw/sec_info parameters to read the central file and not the local one anymore.

 

The syntax with %%RFCSERVER%% is also not correct. If an entry contains syntactically incorrect tags, then it is no longer evaluated  - so it does not work. I also see that you are using tabulators between the tags - this is a bit unreliable, rather use semi-colon.

 

Cheers,

Julius


Viewing all articles
Browse latest Browse all 5338

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>