AP and AR in same interface?
Hi,
We are planning to do the AP and AR of a legacy system in SAP through interface. If both AP and AR are done from a common inventory, can we do both the AP and AR in the same interface? Or can it be done in two different interfaces? What is the difference between doing both in the same interface and two different interface?
Please give me some info on it. I'm new to FI..
Thanks..
Uma.
I can't think of any. If you separate them, you can run them in parallel, so that should be quicker too.
But in the end, I think it's a business decision.
Rob
Similar Messages
-
Webvpn and anyconnect on same interface
Hello !!
Can we configure WebVPN and anyconnect on same interface ?
We have ASA 5520 running with code 9.1(2) with vpn plus license installed. Webvpn is already configured in it. users are already using it. We have a legacy VPN concentrator for RAVPN. Now the client want to move all the RAVPN users from VPN concentrator to ASA using anyconnect.
As we already have webvpn on the asa box, can we configure anyconnect on the same firewall on same interface. ? if so what are the parameters we need to consider.
I am attaching the sh ver of firewall . Any help in this regard is highly appreciated.
Cheers,
Octopus.Hi,
The answer is yes.
Check this for more information:-
https://supportforums.cisco.com/discussion/11181216/webvpn-and-anyconnect
http://www.cisco.com/c/en/us/td/docs/security/asa/asa80/configuration/guide/conf_gd/svc.html
Thanks and Regards,
Vibhor Amrodia -
Is ATA and ATA150 the same interface?
Is this hd compatible with a MacBook?
http://www.newegg.com/Product/Product.asp?Item=N82E16822146053When you boot from the install DVD can you see it under the system profiler or disk utility to initialize it for the Mac? Most HDs come formatted for Windows and while our Mac should still see it, you will want to format it HFS+ for use in your Mac.
-
¿Can Extended and Ethertype (input) ACLs be applied to the same interface?
Hello team:
¿ Is it possible to apply one Extended ACL and one Ethertype ACL, in input mode, to the same interface?
Thank you very much in advance.
Mariela MusitaniThank you very much Borys. I assumed that it was possible, but the documentation was not clear in this context.
regards, Mariela -
Stetting up FTP and SFTP adapters for the same interface
Experts-
I have a situation in which client has a requirement to setup both FTP and SFTP adapters (from adapetive adapters) for the same interface. They want to have a copy of file locally and also want a file to be sent out securly using SFTP. In my interface which was previously developed they have used one business system and added FTP and SFTP to the same. If try to add new Receiver Agreement it will say that the object already exists as the Interface Mapping is same.
Please send me any suggestions which would resolve my problemHi Hari,
As you cannot create two Receiver agreement using only one receiver interface , please create a new receiver Interface, add that in interface determination step and then assing a different channel to new receiver agreement.
If your requirement is to store the file ,i would suggest write the file in your unix directory using NFS( /usr/sap...). then run a AFT job (if already set up in your landscape) to transfer file securly to target destination.Not sure if its feasible in your case otherwise you can use SFTP for the secure transfer.
Best Regards
Srinivas -
EAZYVPN and DMVPN on the same router,same interface
Hi all,
First of all, thanks in advance for the help. I have setup DMVPN and EAZYVPN on one router. Tunnel interface on Spoke one and Spoke two are up/up and show crypto ISakmp sa shows both tunnels are in idle. However, tunnel to Spoke one(10.10.1.1) keep bouncing on and off(see below). Every 30 sec or so, the tunnel gone back to IKE phase while tunnel for spoke two(5.5.5.1) still leave active. THe configuration on the HUB side is the same for both spoke!! show crypto ipsec sec shows both side has the same life time(IOS default). Could that be an IOS debug on the spoke one?
Hub :
Cisco IOS Software, 2800 Software (C2800NM-ADVIPSERVICESK9-M), Version 15.1(3)T2, RELEASE SOFTWARE (fc1)
HUB#sh crypto ipsec security-association
Security association lifetime: 4608000 kilobytes/3600 seconds
Spoke one:
Cisco IOS Software, C2600 Software (C2600-ADVSECURITYK9-M), Version 12.4(8), RELEASE SOFTWARE (fc1)
SPOKE1#sh crypto ipsec security-association
Security association lifetime: 4608000 kilobytes/3600 seconds
HUB#sh crypto isakmp sa
IPv4 Crypto ISAKMP SA
dst src state conn-id status
5.5.5.1 5.5.5.2 QM_IDLE 1002 ACTIVE
10.10.1.1 10.10.1.2 MM_NO_STATE 1134 ACTIVE (deleted)
10.10.1.1 1.1.1.10 QM_IDLE 1126 ACTIVE
10.10.1.1 1.1.1.10 QM_IDLE 1076 ACTIVE
HUB#sh crypto se
HUB#sh crypto session
Crypto session current status
Interface: Serial0/1/1
Username: testuser
Profile: AccountingPro
Group: Accounting
Assigned address: 20.20.20.1
Session status: UP-ACTIVE
Peer: 1.1.1.10 port 60201
IKEv1 SA: local 10.10.1.1/500 remote 1.1.1.10/60201 Active
IPSEC FLOW: permit ip 0.0.0.0/0.0.0.0 host 20.20.20.1
Active SAs: 2, origin: dynamic crypto map
Interface: Serial0/1/1
Username: testuser
Profile: AccountingPro
Group: Accounting
Assigned address: 20.20.20.2
Session status: UP-ACTIVE
Peer: 1.1.1.10 port 49768
IKEv1 SA: local 10.10.1.1/500 remote 1.1.1.10/49768 Active
IPSEC FLOW: permit ip 0.0.0.0/0.0.0.0 host 20.20.20.2
Active SAs: 2, origin: dynamic crypto map
Interface: FastEthernet0/1
Profile: DMVPN
Session status: UP-IDLE
Peer: 5.5.5.2 port 500
IKEv1 SA: local 5.5.5.1/500 remote 5.5.5.2/500 Active
Interface: Serial0/1/1
Profile: DMVPN
Session status: DOWN-NEGOTIATING
Peer: 10.10.1.2 port 500
IKEv1 SA: local 10.10.1.1/500 remote 10.10.1.2/500 Inactive
HUB#
2. My second issue is, I use the same interface(s0/1/1=10.10.1.1) for eazyvpn access. The client from eazyvpn is connected fine,but does not receive traffric back(statics window show no decrypted=0 and reeiced=0). The eazy vpn can't even ping the IP address assigned to the vpn client(20.20.20.2), and the client can only pin 10.10.1.1 address. Reverse router is able but the 20.20.20.0/24 network didn't show up in the ip table of the HUB router!!!
DMVPN AND EAZYVPN SERVER config..
crypto keyring dmvpnkey
pre-shared-key address 0.0.0.0 0.0.0.0 key DMVPNLAB
crypto isakmp policy 1
encr 3des
authentication pre-share
group 2
crypto isakmp policy 10
encr aes
authentication pre-share
group 2
crypto isakmp policy 20
encr aes
authentication pre-share
group 2
crypto isakmp policy 30
encr 3des
hash md5
authentication pre-share
group 2
crypto isakmp policy 40
authentication pre-share
crypto isakmp keepalive 30
crypto isakmp xauth timeout 90
crypto isakmp client configuration group Accounting
key eazypvn
dns 4.2.2.2
wins 4.2.2.2
domain bigBois.com
pool dmAccouting
crypto isakmp profile AccountingPro
match identity group Accounting
client authentication list access_in
isakmp authorization list my_vpn
client configuration address respond
crypto isakmp profile DMVPN
keyring dmvpnkey
match identity address 0.0.0.0
crypto ipsec transform-set DMVPN ah-sha-hmac esp-aes
mode transport
crypto ipsec transform-set EAZYVPN esp-3des esp-md5-hmac
crypto ipsec profile dmvpnlab
set transform-set DMVPN
set isakmp-profile AccountingPro
crypto dynamic-map Remote_Acc 20
set transform-set EAZYVPN
set isakmp-profile AccountingPro
reverse-route
crypto map RemoteAcc client authentication list access_in
crypto map Remote_Acc client authentication list my_vpn
crypto map Remote_Acc 20 ipsec-isakmp dynamic Remote_Acc
interface Loopback0
ip address 192.168.200.1 255.255.255.0
interface Loopback2
ip address 172.16.10.1 255.255.255.0
interface Loopback3
ip address 172.16.15.1 255.255.255.0
interface Tunnel1
bandwidth 10000
ip address 4.4.4.1 255.255.255.0
no ip redirects
ip mtu 1400
no ip next-hop-self eigrp 10
ip nhrp authentication DMVPN
ip nhrp map multicast dynamic
ip nhrp network-id 7940
ip nhrp registration timeout 10
ip tcp adjust-mss 1360
tunnel source Serial0/1/1
tunnel mode gre multipoint
tunnel key 7940
tunnel protection ipsec profile dmvpnlab
interface FastEthernet0/0
description OUTSIDE
ip address 1.1.1.1 255.255.255.0
ip virtual-reassembly in
duplex auto
speed auto
interface FastEthernet0/1
description INSIDE
ip address 5.5.5.1 255.255.255.0
ip nat inside
ip virtual-reassembly in
duplex auto
speed auto
interface Serial0/1/0
no ip address
shutdown
clock rate 2000000
interface Serial0/1/1
description to SPOKE1
ip address 10.10.1.1 255.255.255.0
crypto map Remote_Acc
interface Serial0/3/0
no ip address
shutdown
router eigrp 10
network 4.4.4.0 0.0.0.255
network 5.5.5.0 0.0.0.255
network 10.0.0.0
network 10.10.10.0 0.0.0.3
network 172.16.0.0 0.0.0.255
network 172.16.1.0 0.0.0.255
network 172.16.10.0 0.0.0.255
network 172.16.15.0 0.0.0.255
network 192.168.200.0
ip local pool dmAccouting 20.20.20.1 20.20.20.10
ip forward-protocol nd
ip http server
ip http authentication local
ip http secure-server
THanks a bunch for the help,
ErnestAny ideas why devices keep renewing phase 1?
Thanks, -
PAT between 2 networks on same interface
Hi,
I'm using asa 5505 with 8.4(2) and have the following problem.
I have 2 Networks. each Network has it's own externel Internet-Ip and also Mail-Server.
Here is the example:
Network1:
192.168.1.0/24
Mail-Server: 192.168.1.10
External: 1.1.1.1
Network2:
192.168.2.0/24
Mail-Server: 192.168.2.10
External: 2.2.2.2
Both Networks are connectet through a routing-network to the asa
interface: routed
net: 10.10.10.0/24
Now I want a communication between the two Mailservers with their external Ip-Address.
I did a static NAT from ipnt any to int any or also from int routed to int routed, but nothing worked.
Packet tracer showed at NAT-Lookup where the externel adress of the second Mailserver is passed:
Info
Static translate Network1 to Network1
But it should show a translation from network1 to network1-external
Due to Security reasons, I cannot paste the whole config. I hope the example tells enough about my Problem.
Under 8.0 I did the same configuration with Policy-Nat and it worked.
Thanks for help
Sent from Cisco Technical Support iPad AppHello Roman,
1-Are they behind the same interface?
2-Can you explain a little bit better your network? A diagram would be great
Can you try this:
Object network Server-inside
host: 192.168.1.10
Object network: Server-secondary
host: 192.168.2.10
Object network Natted-inside
host 1.1.1.1
Object network Natted-secondary_server
host 2.2.2.2
Same-security permit intra-interface
nat (routed,routed) source static Server-inside Natted-inside destination static Server-secondary Natted-secondary_server
nat (routed,routed) source static Server-secondary Natted-secondary_server destination static Server-inside Natted-inside
Regards,
Julio -
How to config. different Operations of the same Interface to different BPM
Hi Gurus
I have a very urgent problem.
The requirement is like this:
Customer creates an invoice in A1S and release it. Information of the invoice is retrieved via two service interfaces:
CustomerInvoiceProcessingInvoiceAccountingOut
CustomerInvoiceProcessingReceivablesPayablesOut
with operation NotifyOfInvoice;
These two interfaces will transfer the information into XI and the information will be filled into a BAPI, BAPI_ACC_DOCUMENT_A1S, to R3. Then the finacial document together with the invoice will be created in the R3.
when customer cancels the invoice in A1S, Information of the cancellation is retrieved via the same two service interfaces:
CustomerInvoiceProcessingInvoiceAccountingOut
CustomerInvoiceProcessingReceivablesPayablesOut
with operation NotifyOfInvoiceCancellation;
These two interfaces will transfer the information into XI and the information will be filled into a BAPI, BAPI_ACC_DOCUMENT_REV_POST, to R3. Then the reverse finacial document will be created in R3.
My solution is like this:
1. for invoice creation:
Both messages sent to BPM_1, then send to R3. 3 interface determinations are needed for 3 abstract interfaces.
2. for invoice cancellation:
Both messages sent to BPM_2, then send to R3. 3 interface determinations are needed for 3 abstract interfaces.
My problem is this:
No matter during creation or cancellation, the same interfaces are triggered. The related receiver determination will distribute the information to both of two BPMs. However the information only contains data of one operaton: creation or cancellation. Error messages will appear in monitor for the other BPM. For example, when customer creates an invoice, the information only contains data of creation whereas it is sent to two BPMs via the receiver determination. the BPM for cancellation surely can not deal with this information then error appears.
My question is : how can i solve the problem? How can i avoid the appearance of the error? thanks
Message was edited by:
SAP LCRHi,
In the receiver determination you can route the message to the RIGHT BPM according to the content of the payload. So each time only one BPM is called.
Regards,
Hui -
Same interface name in alert for the synchronous messages
Dear Friends,
I have configured the alert for my interfaces. In the container i have added the message id, sender interface and receiver interface variables. While the error occurs, the alert is getting triggered. But in the alert long text in both the sender and receiver interface the Same 'is_Update'(receiver interface) is only coming.
But in the case of asynchronous interface alerts the sender and receiver interface are coming correctly in the long text of the alert.
Please tell me what might me the problem.
Thanks and Regards
Premthanks for ure reply....
ya i have given the correct interrface names.... this problem is nt only for my interface. this is for all the developers over here...in long text the same interface name is coming for both the sender interface and in receiver interface -
Outbound and Abstract Sync message Interface difference
Hi Experts,
Is there any difference between the input and output messagetype for Outbound/Inbound Synch Message Interface and Abstract Sync Message Interface.
Do we need to mention the same input and output messagetype for both outbound and Abstract or it should be otherway around?
Regards
Sara---Is there any difference between the input and output messagetype for Outbound/Inbound Synch Message Interface and Abstract Sync Message Interface.
No there is not. U can select any message type irrespective of the type of message interface.
---Do we need to mention the same input and output messagetype for both outbound and Abstract or it should be otherway around?
Yes. As per ur requirement u can specify the same.
Regards,
Prateek -
Proxy to Proxy Scenario with sender and receiver on same instance
Hi,
I have a scenario to integrate Erecruit to HR system usng standard content. Both the Erecruiting and HR are on same instance so my sender and receiver is the same system. Standard ABAP proxies are provided.
Now I need some help in how to configure the channels and the agreements as both the sender and receiver are on same instance. Do i need to use parties?
do i have to create a sender communication channel?
Please let me know the stps required in configuration for this scenario.
Thanks in advance.Hey
It does not matter if your sender and receiver are same system or different systems,the configuration steps will be the same.
In your case you would need
1 Receiver determination
1 interface determination
1 receiver agreement
1 receiver communication channel(of type XI adapter,this will connect to HR system).
No party or sender communication channel or sender agreement are required.
You need to have configured 1 business system for HR system in SLD though.
Thanx
Aamir
Edited by: Aamir Suhail on Jul 23, 2008 7:36 PM -
Multiple targets for a same interface
Hi,
I am having a scenario that, a single source table should be mapped to two target oracle tables.
Is the only way is to create two interfaces. Cant we have the same interface in which two target tables are assigned?
Thanks in Advance,
Ram Mohan T.A single interface targets only a single table/datastore.
If you are having to load the data from an external source, and load into two tables, an approach is to separate the load and integration phases. Have one interface load the data into a temporary table in the work schema, then two interfaces which read that data and load it into your target tables. (You could also use only two interfaces, where you set the integration KM option to DELETE_TEMPORARY_OBJECTS in the first to no, and read the loading table created there in the first interface as the source for your second interface). I prefer the 3 interface option, it ends up being cleaner and clearer. -
IPS not detecting packets Entering & Exiting Same Interface
Hi,
Consider scenario :-
Host A--->Router B--->Router C
All are in the same subnet
Router C also has an active interface on another subnet.
When I telnet from A to C (interface with ip address in another subnet),
I force traffic from A to C to pass through B, by setting static routes AND ** DISABLING IP REDIRECTS ***
Trafic flows from A to B IN through Fa0/0, and OUT again through Fa0/0 from B to C
I have ACL's (permit/log) that show this flow !!!!
I also have IPS enabled in/out on Fa0/0 on router B.
However, traffic flowing through Router B, which enters / exits the same interface, does not get picked up by IPS. (I trigger signatures)
Is this normal ?? Or am I missing something ?I don't use the router IPS, but I'll give it a shot;-) I don't understand the network config. I'll try to redraw the network to see if I understand what you're saying:
Host A
(NET1/IP1)
|
-------- (NET1/IP3) Router C (NET2/IP4)---
|
(NET1/IP2)
Router B
Host A uses Router B as its gateway to NET2 and since redirects are disabled on router B, all traffic from Host A to IP4 flows through router B. If the diagram above is correct though, return traffic from router C will not be routed through Router B because the destination is on the same network as router C. How are you getting return traffic to flow through router B?
Based on the following doc:
http://www.cisco.com/application/pdf/en/us/guest/products/ps6634/c1244/cdccont_0900aecd80327257.pdf
If you're attempting to fire atomic signatures (single packet) then signatures should still fire anyway when inspected inbound. If you're attempting to trigger a stateful signature then this would be a plausible explanation. -
Relay traffic out same interface
Is it possible to relay traffic out of the same interface? For instance we have a computer on the Internet that only is accessible from our network. I'd like users to connect to our network, look at the ACL, and then connect to the remote computer. So basically I'm going right back out the same interface. VPN->outside interface->Internet. I'd still want split tunneling to be enabled and have this apply to only a specific IP or subnet. Is this possible?
This is the packet tracer result:
Phase: 1
Type: ROUTE-LOOKUP
Subtype: input
Result: ALLOW
Config:
Additional Information:
in 0.0.0.0 0.0.0.0 outside
Phase: 2
Type: ROUTE-LOOKUP
Subtype: input
Result: ALLOW
Config:
Additional Information:
in 0.0.0.0 0.0.0.0 outside
Phase: 3
Type: ACCESS-LIST
Subtype:
Result: DROP
Config:
Implicit Rule
Additional Information:
Result:
input-interface: outside
input-status: up
input-line-status: up
output-interface: outside
output-status: up
output-line-status: up
Action: drop
Drop-reason: (acl-drop) Flow is denied by configured rule
I can see the traffic comming from the VPN client to the IP, so the route is working. I get a teardown and built message in the log, but nothing saying the traffic is denied.
I think this info should cover what you're looking for:
group-policy GroupPolicy_ZSSL attributes
wins-server none
dns-server value 192.168.1.8 192.168.1.47
vpn-tunnel-protocol ikev2 ssl-client
default-domain value company.com
webvpn
anyconnect profiles value ZSSL_client_profile type user
username company password xxxxxxxxxxxxxx encrypted privilege 15
tunnel-group companyVPN type remote-access
tunnel-group companyVPN general-attributes
address-pool VPNPool
authentication-server-group MicrosoftIAS LOCAL
accounting-server-group MicrosoftIAS
default-group-policy companyVPN
password-management
tunnel-group companyVPN ipsec-attributes
ikev1 pre-shared-key ***** -
Running same interface in muliple sites
Hi Giuys,
I have a requirement where i need to run similar interface at different clients sites.
i.e source table and target tables are same strucutre only filter will change and i think we can change
filter dynamically though global variable.
The question is how can we run same interface in diffrent clients places i.e traget schema/db names will change.I can do this easily by copying one interface and build individual interfaces for different clients.
But i do not want to do like that i just want one interface connecting to different sites.iam sure it is something
with topology? Can you guys please give me some advise here..
Cheersok,so effectively as notmal we need to create n number of contexts and physical schemas,data servers etc and use those contexts when we run them through scheduler,is that right?So on that time we will be having many copies of the same interface for mutiple sites right?
cheers
Edited by: vas on 15-Mar-2012 07:30
Edited by: vas on 15-Mar-2012 07:32
Maybe you are looking for
-
My laptop hard drive crashed last week and I had to have it replaced. I had been using Firefox for about 18 months and had stored a number of GREAT websites for my career search. When I got my computer back from the shop, I had to reload all of my pr
-
Set up Remote Access for Mac Mini
I recently bought a Mac Mini and set it up at home. It is running on Mac OS X 10.8.3, and runs on Server 2.2.1 and Airport Utilities 6.2. I would like to be able to access the Mac Mini server from outside my home. Does anyone know the procedure of se
-
I recently upgraded one of my production databases to Oracle 10g from 9i. Everything was working perfectly. Now when I try to launch Enterprise manager I get "Server Error: Can't connect because of networking problems". I tried to stop and start the
-
Using JEditorPane.selected() with embedded tags.
Ok, I've been searching the forums and tutorials for about an hour tonight, and I've seen this question asked in many forms but never answered. I am writing an applet which uses embedded HTML and some custom tags in a sub-class of JEditorPane that I
-
Hi Guys I'm trying to insert a flash video file (FLV) that has the controls as a separate swf using SWFObject. The flash was created in Flash 8. I'm not sure of the actual code I need to get this to work though. The html file that should contain the