SAP Landscape Management 3.0, Enterprise Edition

Network Isolation

Prerequisites

You configure systems.

For more information, see Configuring Systems.

Context

Configuring Outgoing Connections for System Isolation

You configure allowed outgoing connections for system isolation.

Prerequisites

  • You have configured the following monitoring settings:

    • Valid host names for outgoing connections

    • Valid ports for outgoing connections

  • Ensure that SAP Landscape Management applied your configured monitoring settings to all isolated systems.

    For more information, see Configuring Monitoring Settings.

  • To use the configured outgoing connections as template for system provisioning, the system must be enabled for cloning or copying.

    For more information, see Enabling Systems for Provisioning Operations.

  • To apply the configured outgoing connections to all instances of the system, the system must be a clone or copy of an existing system.

Context

Procedure

  1. Choose Start of the navigation pathConfiguration Next navigation step SystemsEnd of the navigation path.
  2. Select the system for which you want to configure outgoing connections for isolation.
  3. In the System Details screen area, choose Edit.
  4. Navigate to the Network Isolation step.

    The connections for the host specified in the Read Connections of Host field are displayed.

  5. To remove a connection on the system, select it and choose Remove.
  6. To allow more connections on the system, choose Add and provide the following information.
    Option Description

    Enable Network Fencing

    To remove isolation for a copied system, deselect the checkbox.

    You have to ensure, that all necessary changes to the copy are applied.

    You cannot disable network fencing for cloned systems.

    Rule Type

    • To allow communication to a host on all ports, choose Host.

    • To allow communication to a specific host and to all other hosts on given ports or services, choose Host & Port.

    • To allow communication to all hosts on the defined port or service, choose Port.

    Target Host Name

    Enter the host name for the connection.

    Target Port

    Enter the port or service for the connection.

    Update existing Fencing Rules

    • If the Enable Network Fencing checkbox is selected, SAP Landscape Management applies the firewall rules to all instances of this system.

    • If the Enable Network Fencing checkbox is not selected, SAP Landscape Management removes the firewall rules of all instances from the system.

  7. Save your entries.