Your browser does not allow storing cookies. We recommend enabling them.

SSH Tectia

SSH Tectia Configuration Generation

The SSH Tectia Server configuration requires tunneling settings to allow users in group sapuser to tunnel connections to any ports used by the SAP GUI traffic on the SAP Application Server. Remote tunneling on servers (via the SSH Tectia Server running on the SAP Application Server) is denied for everyone.

The configuration settings are done on tab Configurations → Edit Configurations → SSH Tectia under the SSH Tectia Server configuration Rules → <rule-set> → Tunnels view.

Example tunneling settings are shown in Figure 5.15.

Configuring tunneling settings for SAP application server

Figure 5.15. Configuring tunneling settings for SAP application server

The SSH Tectia Client software on the user workstations needs to be configured to use transparent TCP tunneling in handling the SAP GUI traffic. Figure 5.16 shows the tunneling rule settings for capturing and encrypting all SAP traffic generated by the sap.example.exe application and related to any host address or listen port. The user name and the destination definition will be extracted from the information sent by the SAP application.

The configuration settings are done on tab Configurations → Edit Configurations → SSH Tectia under the SSH Tectia Client configuration Transparent tunneling → Filters view.

Example settings are shown in Figure 5.16.

Setting the tunneling rules

Figure 5.16. Setting the tunneling rules


 

 
PrivX
 

 

 
What to read next:

  • Reduce Secure Shell risk. Get to know the NIST 7966.



    The NISTIR 7966 guideline from the Computer Security Division of NIST is a direct call to action for organizations regardless of industry and is a mandate for the US Federal government.
    Download now
  • ISACA Practitioner Guide for SSH



    With contributions from practitioners, specialists and SSH.COM experts, the ISACA “SSH: Practitioner Considerations” guide is vital best practice from the compliance and audit community.
    Download now