Need help in configuring CHARM with R/3 System landscape with seven systems
Hi All,
we are planning to configure CHARM for our R/3 landscape.our current STMS includes seven systems.in the current STMS the transports flow as below.
D20->C20->C21->C22->C23->T20->P20
we require the transports to move in the same way as stated above even after CHARM is configured
1.please let me know if we can configure CHARM with seven systems.
2.if yes, how would the import happen( ie Action for import appears for all systems?).
Regards,
Anand Reddy
HI andy,
the transports will move in the following order.
D20(DEV)->C20(Consolidation)->C21(integ)->C22(reg)->C23(unit)->T20(final test)->P20(production)
transport will start in D20,then imported C20 followed by C21,C22,C23,T20 imports and finally reach P20
the systems are not in parallel they are one behind the other
Anand Reddy
Similar Messages
-
I have a PC and a need help to configure my external hard disk on my network. Thanks
I have a PC and a need help to configure my external hard disk on my network. Thanks
If you mean you wish to plug a USB drive into the Airport Extreme router (or TC not express) that is easy..
The disk must be formatted FAT32.. as if.. stay away from FAT .. or HFS+ ie Mac OS extended Journaled.
Format the disk on a Mac is best.. and even use GUID partition scheme not MBR.
The PC has no issue writing and reading files because this is a network drive.. The PC does not write to the drive.. it writes files to the Airport OS which writes and reads the disk and passes the info using standard windows SMB.. To the windows computer it will be a Windows NT server.. FAT32 setup.
If your setup is different.. to my hugely guessed assumptions.. give details.. always helps to have.. make and model.
Make and model of disk.. make and model of router.. how the setup will be done.. what windows OS you run.. etc etc.
As it stands your question could have nothing to do with apple at all.. other than you posted in a forum so I guess there is something apple in there somewhere. -
Hi All,
I need help on Configuring the Site to Site VPN from Cisco 2811 to Websense Cloud for web Traffic redirect
2811 having C2800NM-ADVIPSERVICESK9-M
2811 router connects to the Internet SW then connects to the Internet router.
Note- For Authentication am using the Device ID & Pre share key. I am worried as all user traffic goes with PAT and not firing up my tunnel for port 80 traffic. Can you please suggest what can be the issue ?
Below is router config for VPN & NAT
crypto keyring ISR_Keyring
pre-shared-key hostname vpn.websense.net key 2c22524d554556442d222d565f545246
crypto isakmp policy 1
encr 3des
authentication pre-share
group 2
crypto isakmp keepalive 10
crypto isakmp profile isa-profile
keyring ISR_Keyring
self-identity user-fqdn [email protected]
match identity user vpn-proxy.websense.net
crypto ipsec transform-set ESP-NULL-SHA esp-null esp-sha-hmac
crypto map GUEST_WEB_FILTER 10 ipsec-isakmp
set peer vpn.websense.net dynamic
set transform-set ESP-NULL-SHA
set isakmp-profile isa-profile
match address 101
interface FastEthernet0/1
description connected to Internet
ip address 216.222.208.101 255.255.255.128
ip access-group HVAC_Public in
ip nat outside
ip virtual-reassembly
duplex full
speed 100
no cdp enable
crypto map GUEST_WEB_FILTER
access-list 101 permit tcp 192.168.8.0 0.0.3.255 any eq www
access-list 103 deny ip 192.168.8.0 0.0.3.255 host 85.115.41.187 log
access-list 103 deny ip 192.168.8.0 0.0.3.255 host 85.115.41.181 log
access-list 103 deny ip 192.168.8.0 0.0.3.255 host 85.115.41.182 log
access-list 103 deny ip 192.168.8.0 0.0.3.255 86.111.216.0 0.0.1.255
access-list 103 deny ip 192.168.8.0 0.0.3.255 116.50.56.0 0.0.7.255
access-list 103 deny ip 192.168.8.0 0.0.3.255 86.111.220.0 0.0.3.255
access-list 103 deny ip 192.168.8.0 0.0.3.255 103.1.196.0 0.0.3.255
access-list 103 deny ip 192.168.8.0 0.0.3.255 177.39.96.0 0.0.3.255
access-list 103 deny ip 192.168.8.0 0.0.3.255 196.216.238.0 0.0.1.255
access-list 103 permit ip 192.168.8.0 0.0.3.255 any
ip nat pool mypool 216.222.208.101 216.222.208.101 netmask 255.255.255.128
ip nat inside source list 103 interface FastEthernet0/1 overload
ip nat inside source route-map nonat pool mypool overloadHow does Websense expect your source IPs in the tunnel? 192.168.8.0 0.0.3.255 or PAT'ed 216.222.208.101 ?
Check
show crypto isakmp sa
show crypto ipsec sa
show crypto session
You'd better remove the preshared key from your post. -
Need help. I am running a 27 in imac with 16 gigs of ram. Photoshop runs really fast, except when opening files. It takes 5-10 minutes to open even a small file of 1 meg. I cleaned and validated all the fonts and removed all questionable fonts. Reset preferences and still have problem. Slow to open and in force quit "Photoshop not responding" At this point should I uninstall and start over.
What are the performance Preferences?
-
Need help on displaying the callers name on ip phone with cme using external directory
Hello Guys,
Need help on displaying the callers name on ip phone with cme while using external directory
Thank you,
KhajaThanks for your help,
Does it 100% work with CME. We use SIP and 2ring for external directory? Thanks you. -
I need help findin my sons iPod n I set up with different iCloud account n never installed find my device n location map is off how do I locate device
Jenniferp27.jp wrote:
...n never installed find my device n location map is off how do I locate device
Then you cannot locate it electronically.
What to do if your iOS device is lost or stolen
http://support.apple.com/kb/HT5668 -
i bought my iphone secondhand, and the previous owner didnt deltete his find my iphone account, so when i restored it i know cant access my phone, i need help as i have no way of getting intouch with the previous owner whatsoever :/ help!
Welcome to the Apple community.
Unfortunately, you cannot do very much with your phone unless you get assistance from the previous owner, they should either provide you with the password to unlock it or remove their account from the phone entirely remotely through iCloud.com > Find My Phone. -
Need urgent help in configuring Client to Site IPSec VPN with Hairpinning on Cisco ASA5510 - 8.2(1).
The following is the Layout:
There are two Leased Lines for Internet access - 1.1.1.1 & 2.2.2.2, the latter being the Standard Default route, the former one is for backup.
I have been able to configure Client to Site IPSec VPN
1) With access from Outside to only the Internal Network (172.16.0.0/24) behind the asa
2) With Split tunnel with simultaneous assess to internal LAN and Outside Internet.
But I have not been able to make tradiotional Hairpinng model work in this scenario.
I followed every possible sugestions made in this regard in many Discussion Topics but still no luck. Can someone please help me out here???
Following is the Running-Conf with Normal Client to Site IPSec VPN configured with No internat Access:
LIMITATION: Can't Boot into any other ios image for some unavoidable reason, must use 8.2(1)
running-conf --- Working normal Client to Site VPN without internet access/split tunnel
ASA Version 8.2(1)
hostname ciscoasa
domain-name cisco.campus.com
enable password xxxxxxxxxxxxxx encrypted
passwd xxxxxxxxxxxxxx encrypted
names
interface GigabitEthernet0/0
nameif internet1-outside
security-level 0
ip address 1.1.1.1 255.255.255.240
interface GigabitEthernet0/1
nameif internet2-outside
security-level 0
ip address 2.2.2.2 255.255.255.224
interface GigabitEthernet0/2
nameif dmz-interface
security-level 0
ip address 10.0.1.1 255.255.255.0
interface GigabitEthernet0/3
nameif campus-lan
security-level 0
ip address 172.16.0.1 255.255.0.0
interface Management0/0
nameif CSC-MGMT
security-level 100
ip address 10.0.0.4 255.255.255.0
boot system disk0:/asa821-k8.bin
boot system disk0:/asa843-k8.bin
ftp mode passive
dns server-group DefaultDNS
domain-name cisco.campus.com
same-security-traffic permit inter-interface
same-security-traffic permit intra-interface
object-group network cmps-lan
object-group network csc-ip
object-group network www-inside
object-group network www-outside
object-group service tcp-80
object-group service udp-53
object-group service https
object-group service pop3
object-group service smtp
object-group service tcp80
object-group service http-s
object-group service pop3-110
object-group service smtp25
object-group service udp53
object-group service ssh
object-group service tcp-port
object-group service udp-port
object-group service ftp
object-group service ftp-data
object-group network csc1-ip
object-group service all-tcp-udp
access-list INTERNET1-IN extended permit ip host 1.2.2.2 host 2.2.2.3
access-list CSC-OUT extended permit ip host 10.0.0.5 any
access-list CAMPUS-LAN extended permit tcp 172.16.0.0 255.255.0.0 any eq www
access-list CAMPUS-LAN extended permit tcp 172.16.0.0 255.255.0.0 any eq https
access-list CAMPUS-LAN extended permit tcp 172.16.0.0 255.255.0.0 any eq ssh
access-list CAMPUS-LAN extended permit tcp 172.16.0.0 255.255.0.0 any eq ftp
access-list CAMPUS-LAN extended permit udp 172.16.0.0 255.255.0.0 any eq domain
access-list CAMPUS-LAN extended permit tcp 172.16.0.0 255.255.0.0 any eq smtp
access-list CAMPUS-LAN extended permit tcp 172.16.0.0 255.255.0.0 any eq pop3
access-list CAMPUS-LAN extended permit ip any any
access-list csc-acl remark scan web and mail traffic
access-list csc-acl extended permit tcp any any eq smtp
access-list csc-acl extended permit tcp any any eq pop3
access-list csc-acl remark scan web and mail traffic
access-list INTERNET2-IN extended permit tcp any host 1.1.1.2 eq 993
access-list INTERNET2-IN extended permit tcp any host 1.1.1.2 eq imap4
access-list INTERNET2-IN extended permit tcp any host 1.1.1.2 eq 465
access-list INTERNET2-IN extended permit tcp any host 1.1.1.2 eq www
access-list INTERNET2-IN extended permit tcp any host 1.1.1.2 eq https
access-list INTERNET2-IN extended permit tcp any host 1.1.1.2 eq smtp
access-list INTERNET2-IN extended permit tcp any host 1.1.1.2 eq pop3
access-list INTERNET2-IN extended permit ip any host 1.1.1.2
access-list nonat extended permit ip 172.16.0.0 255.255.0.0 172.16.0.0 255.255.0.0
access-list DNS-inspect extended permit tcp any any eq domain
access-list DNS-inspect extended permit udp any any eq domain
access-list capin extended permit ip host 172.16.1.234 any
access-list capin extended permit ip host 172.16.1.52 any
access-list capin extended permit ip any host 172.16.1.52
access-list capin extended permit ip host 172.16.0.82 host 172.16.0.61
access-list capin extended permit ip host 172.16.0.61 host 172.16.0.82
access-list capout extended permit ip host 2.2.2.2 any
access-list capout extended permit ip any host 2.2.2.2
access-list campus-lan_nat0_outbound extended permit ip 172.16.0.0 255.255.0.0 192.168.150.0 255.255.255.0
pager lines 24
logging enable
logging buffered debugging
logging asdm informational
mtu internet1-outside 1500
mtu internet2-outside 1500
mtu dmz-interface 1500
mtu campus-lan 1500
mtu CSC-MGMT 1500
ip local pool vpnpool1 192.168.150.2-192.168.150.250 mask 255.255.255.0
ip verify reverse-path interface internet2-outside
ip verify reverse-path interface dmz-interface
ip verify reverse-path interface campus-lan
ip verify reverse-path interface CSC-MGMT
no failover
icmp unreachable rate-limit 1 burst-size 1
asdm image disk0:/asdm-621.bin
no asdm history enable
arp timeout 14400
global (internet1-outside) 1 interface
global (internet2-outside) 1 interface
nat (campus-lan) 0 access-list campus-lan_nat0_outbound
nat (campus-lan) 1 0.0.0.0 0.0.0.0
nat (CSC-MGMT) 1 10.0.0.5 255.255.255.255
static (CSC-MGMT,internet2-outside) 2.2.2.3 10.0.0.5 netmask 255.255.255.255
access-group INTERNET2-IN in interface internet1-outside
access-group INTERNET1-IN in interface internet2-outside
access-group CAMPUS-LAN in interface campus-lan
access-group CSC-OUT in interface CSC-MGMT
route internet2-outside 0.0.0.0 0.0.0.0 2.2.2.5 1
route internet1-outside 0.0.0.0 0.0.0.0 1.1.1.5 2
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
timeout tcp-proxy-reassembly 0:01:00
dynamic-access-policy-record DfltAccessPolicy
aaa authentication ssh console LOCAL
aaa authentication enable console LOCAL
http server enable
http 10.0.0.2 255.255.255.255 CSC-MGMT
http 10.0.0.8 255.255.255.255 CSC-MGMT
http 1.2.2.2 255.255.255.255 internet2-outside
http 1.2.2.2 255.255.255.255 internet1-outside
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart
crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac
crypto ipsec transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac
crypto ipsec transform-set ESP-DES-SHA esp-des esp-sha-hmac
crypto ipsec transform-set ESP-DES-MD5 esp-des esp-md5-hmac
crypto ipsec transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac
crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac
crypto ipsec transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac
crypto ipsec transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac
crypto ipsec transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac
crypto ipsec transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac
crypto ipsec security-association lifetime seconds 28800
crypto ipsec security-association lifetime kilobytes 4608000
crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set pfs group5
crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5
crypto map internet2-outside_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP
crypto map internet2-outside_map interface internet2-outside
crypto ca trustpoint _SmartCallHome_ServerCA
crl configure
crypto ca certificate chain _SmartCallHome_ServerCA
certificate ca xyzxyzxyzyxzxyzxyzxyzxxyzyxzyxzy
a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as
a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as
a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as
a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as
a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as
a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as
a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as
a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as
a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as
a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as
a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as
a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as
a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as
a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as a67a897as
a67a897as a67a897as a67a897as a67a897as a67a897as
quit
crypto isakmp enable internet2-outside
crypto isakmp policy 10
authentication pre-share
encryption aes
hash md5
group 2
lifetime 86400
telnet 10.0.0.2 255.255.255.255 CSC-MGMT
telnet 10.0.0.8 255.255.255.255 CSC-MGMT
telnet timeout 5
ssh 1.2.3.3 255.255.255.240 internet1-outside
ssh 1.2.2.2 255.255.255.255 internet1-outside
ssh 1.2.2.2 255.255.255.255 internet2-outside
ssh timeout 5
console timeout 0
threat-detection basic-threat
threat-detection statistics access-list
no threat-detection statistics tcp-intercept
webvpn
group-policy VPN_TG_1 internal
group-policy VPN_TG_1 attributes
vpn-tunnel-protocol IPSec
username ssochelpdesk password xxxxxxxxxxxxxx encrypted privilege 15
username administrator password xxxxxxxxxxxxxx encrypted privilege 15
username vpnuser1 password xxxxxxxxxxxxxx encrypted privilege 0
username vpnuser1 attributes
vpn-group-policy VPN_TG_1
tunnel-group VPN_TG_1 type remote-access
tunnel-group VPN_TG_1 general-attributes
address-pool vpnpool1
default-group-policy VPN_TG_1
tunnel-group VPN_TG_1 ipsec-attributes
pre-shared-key *
class-map cmap-DNS
match access-list DNS-inspect
class-map csc-class
match access-list csc-acl
policy-map type inspect dns preset_dns_map
parameters
message-length maximum 512
policy-map global_policy
class csc-class
csc fail-open
class cmap-DNS
inspect dns preset_dns_map
service-policy global_policy global
prompt hostname context
Cryptochecksum: y0y0y0y0y0y0y0y0y0y0y0y0y0y
: end
Neither Adding dynamic NAT for 192.168.150.0/24 on outside interface works, nor does the sysopt connection permit-vpn works
Please tell what needs to be done here, to hairpin all the traffic to internet comming from VPN Clients.
That is I need clients conected via VPN tunnel, when connected to internet, should have their IP's NAT'ted against the internet2-outside interface address 2.2.2.2, as it happens for the Campus Clients (172.16.0.0/16)
I'm not much conversant with everything involved in here, therefore please be elaborative in your replies. Please let me know if you need any more information regarding this setup to answer my query.
Thanks & Regards
maxsHi Jouni,
Thanks again for your help, got it working. Actually the problem was ASA needed some time after configuring to work properly ( ?????? ). I configured and tested several times within a short period, during the day and was not working initially, GUI packet tracer was showing some problems (IPSEC Spoof detected) and also there was this left out dns. Its working fine now.
But my problem is not solved fully here.
Does hairpinning model allow access to the campus LAN behind ASA also?. Coz the setup is working now as i needed, and I can access Internet with the NAT'ed ip address (outside-interface). So far so good. But now I cannot access the Campus LAN behind the asa.
Here the packet tracer output for the traffic:
packet-tracer output
asa# packet-tracer input internet2-outside tcp 192.168.150.1 56482 172.16.1.249 22
Phase: 1
Type: ACCESS-LIST
Subtype:
Result: ALLOW
Config:
Implicit Rule
Additional Information:
MAC Access list
Phase: 2
Type: FLOW-LOOKUP
Subtype:
Result: ALLOW
Config:
Additional Information:
Found no matching flow, creating a new flow
Phase: 3
Type: ROUTE-LOOKUP
Subtype: input
Result: ALLOW
Config:
Additional Information:
in 172.16.0.0 255.255.0.0 campus-lan
Phase: 4
Type: ROUTE-LOOKUP
Subtype: input
Result: ALLOW
Config:
Additional Information:
in 192.168.150.1 255.255.255.255 internet2-outside
Phase: 5
Type: ACCESS-LIST
Subtype: log
Result: ALLOW
Config:
access-group internnet1-in in interface internet2-outside
access-list internnet1-in extended permit ip 192.168.150.0 255.255.255.0 any
Additional Information:
Phase: 6
Type: IP-OPTIONS
Subtype:
Result: ALLOW
Config:
Additional Information:
Phase: 7
Type: CP-PUNT
Subtype:
Result: ALLOW
Config:
Additional Information:
Phase: 8
Type: VPN
Subtype: ipsec-tunnel-flow
Result: ALLOW
Config:
Additional Information:
Phase: 9
Type: NAT-EXEMPT
Subtype: rpf-check
Result: ALLOW
Config:
Additional Information:
Phase: 10
Type: NAT
Subtype:
Result: DROP
Config:
nat (internet2-outside) 1 192.168.150.0 255.255.255.0
match ip internet2-outside 192.168.150.0 255.255.255.0 campus-lan any
dynamic translation to pool 1 (No matching global)
translate_hits = 14, untranslate_hits = 0
Additional Information:
Result:
input-interface: internet2-outside
input-status: up
input-line-status: up
output-interface: internet2-outside
output-status: up
output-line-status: up
Action: drop
Drop-reason: (acl-drop) Flow is denied by configured rule
The problem here as you can see is the Rule for dynamic nat that I added to make hairpin work at first place
dynamic nat
asa(config)#nat (internet2-outside) 1 192.168.150.0 255.255.255.0
Is it possible to access both
1)LAN behind ASA
2)INTERNET via HAIRPINNING
simultaneously via a single tunnel-group?
If it can be done, how do I do it. What changes do I need to make here to get simultaneous access to my LAN also?
Thanks & Regards
Abhijit -
hi i need help, im new on mac, i bought the las year a macbook pro 13's late 2011 with 4 gb of ram and 500 gb of hdd, i5 proccesor of 2.4. the mbp was working ok, until yesterday, i was working on keynote and then, it started to getting really slow, then it frozzen, and the little umbrella start to appears,i tried every thing, i shut down the power button, wait a minute then i power up, and nothing, i run the ccleaner, i check the hdd status, the ram, and everything was ok, i even boot up the system like fabric and still nothing i got the umbrella everything than i run an application. please please help me.
what i have to do?????????????Try a Safe Boot to clear the dyld_shared_cache (dynamic loader cache)
SafeBoot http://support.apple.com/kb/HT1564
Safe Boot, which automatically rebuilds this cache (among other things). -
STMS Route configuration in Three system Landscape with DEV,QA and PRD
Hi
We have Three system landscape.i.e DEV,Quality and PRD
Before Somebody configured the STMS by selecting standard two system land scape ( Dev and QAS)
We Have Installed Production Server And Added into Existing STMS Configuration
Now Three Systems Showing, In Import Overviw Screen
How Can I Create Route Between Three systems
What I am Asking Is Without Delet Old Roots
Can i Create it are Not
regards
NSNRefer these links:
http://help.sap.com/saphelp_erp2005/helpdata/en/1c/2ddc0901db11d284870000e8a57770/frameset.htm
http://help.sap.com/saphelp_erp2005/helpdata/en/44/b4a0137acc11d1899e0000e829fbbd/frameset.htm
Regards,
Ravi -
System landscape with one missing Hana (2 Hana / 3 ECC)
Hi all,
We’re currently working in a landscape with only 2 Hana: one for DEV+Integration (to be connected to 2 ECC : DEV and INT) and the other for the production system (connected to the prod ECC). Any idea on how we can deliver our tested developments on the same environment (the dev) for integration testing ?
On the DEV system we would like to have a development version of each object connected to the DEV ECC and an integration version of the same objects connected to the INT ECC.
We can copy all objects from one package (dev) to another (int), change the authoring schema and adapt all the inside references. I’m looking for an easier way, ideally with delivery units (which should be the way we will deliver our views on the production system).
Any input will be appreciated…
Regards,
FredDear Beate;
Thanks for your question!
One of the key advantages and strategic benefits from our SAP SLcM solution is the fact that we are directly/automatically connected with core (academic supporting) backoffice processes like HR and Finance.
On the HR side we share for example the Organizational Management foundation and at the Finance side we are directly tapped into the core financial processes powered by the FICA engine of ERP.
If there are no strong/solid compelling reasons (beside the emotional ones ) to have a point-solution installation of SLcM we always recommend to have SLcM running inside the existing available business suite/ERP. Why?
Direct, automatic integration with HCM (HR)
Direct, automatic integration with FICA (Finance), from tuition fee to collection and distribution to general ledger)
Re-use of key supporting business suite engines like:
1. Workflow
2. Authorisation module
3. DMS
Maintenance of only one system instead of multiple ones
You avoid building and maintaining extra 'interfaces' between ERP1 and ERP2+SLcM.
Etc.
Hope this helps!
Let me know if you have any other concerns or want to have a call, please drop me an e-mail.
Kind regards
Rob
SAP IBS Solution Management (Higher) Education & Research. -
Indirect Role Assignment with HR-ORG in a system landscaper with CUA
Hi all,
we have 2 SAP systems:
1) SAP ECC6 (with composite roles)
2) SAP HR with PA and OM
We would like to assign SAP ECC6 roles through HR-OM.
Since HR-OM is not on the same ECC6 system, we would like to try the logic: HR-OM -> CUA -> ECC6
There are several documents that describe this situation (ex. SCUR351).
From PFCG point of view, we should create a composite role in CUA system which include simple roles of child system.
If we try to create a composite role in CUA central system, we can insert only simple roles available in central system (and not in child).
Any experience on this scenario ?
Pros vs cons ?
Are the different possible scenarios ?
Many thanks...
AndreaWhole idea of CUA is to manage your roles and users centrally, on the contrary you can manage the roles/profiles by setting up the attributes for the CUA thorugh Central user Management console - SCUM Transaction.
CUA has its own pros -
Central rep,Users Sync,Role Provisioning statergy - Global composites(consists of individual child roles) Distibuted model -Provisioing at individual child systems for roles, etc.Central user store,easy maintenance.
on the contrary - change documents is always a concern ( because cua uses - interface Ids or the RFC ids to push the idocs from cua to child system), CUA maintenance while system refresh - Copied distribution models have to be deleted and re-created, system backups has to be defined per you distribution model, password maintenance if defined global then Child systems act as inactive nodes, reading the roles into cua which are created in childs so as to establish a pointer to that system.
It also depends on the number of systems you have in your landscape so that you can calculate the overhead and then have a Go -no-Go decison on CUA.
Overall, I consider CUA as a good approach provided we streamline the process of provisioning, de-provisioning per the cua standards.
Rakesh -
Transports on system landscape with no test environment
Hi,
Please share your experience about transporting from BWD to BWP. I have normally worked with BWD, BWQ, BWP, where we have the chance to test our transports on BWQ before moving the perfect changes to BWP. What precautions should I take when working and dealing with the landscape with no test instance?
Thanks
"<i>Public opinion is a weak tyrant compared with our own private opinion. What a man thinks of himself, that is which determines, or rather indicates, his fate.</i>" ~ Henry David Thoreau, US Transcendentalist author (1817 - 1862)Hi all,
Certainly I see and hear that smaller companies don't have enough funds to implement 3- system landscape, but I don't see why they would want to do that - better save money then and just do ABAP R3 reporting if all you will have is just implementing one module. Aren't you suppose to have sufficient funds in order to maintain and have SAP R3 and BW running? When they start wanting to implement more modules, then it will get clumsy and unstructured. They would have to spend more effort in doing the workaround and dealing with an unruly environment.
Thanks
"<i>When the character of a man is not clear to you, look at his friends.</i>" ~ Japanese Proverb
"<i>Nothing is easier than to denounce the evildoer; nothing is more difficult than to understand him.</i>" ~ Fyodor Dostoevsky, Russion Literaturer (1821 - 1881)
"<i>Be smart and know who you're dealing with...But again who wants to</i>" ~ Anonymous -
Need Help in configuring workflow Notification Mailer with IMAP
Hi,
i've configured the notification mailer successfully with SMTP and it's working fine , users can receive mail notifications but the INBOUND processing doesn't work.
i've created a new mail account on the IMAP server (Outlook 2007), but when configure the Notification mailer from OAM it gives me the following error:
Unable to connect to the mail account. Check the host, user name and password.
i tried many documents from the web but till know i can't have a solution for this issue.
EBS version : 11.5.10.2
Please note that i don't have access to MetaLink.
please help if you have any suggestions.
Thanks..
Edited by: Smarteng on Mar 13, 2012 6:53 AMi've configured the notification mailer successfully with SMTP and it's working fine , users can receive mail notifications but the INBOUND processing doesn't work.
i've created a new mail account on the IMAP server (Outlook 2007), but when configure the Notification mailer from OAM it gives me the following error:
Unable to connect to the mail account. Check the host, user name and password.
https://forums.oracle.com/forums/search.jspa?threadID=&q=%22Unable+to+connect+to+the+mail+account%22&objID=c3&dateRange=all&userID=&numResults=15&rankBy=10001
Thanks,
Hussein -
Need help in configuring the Oracle app server with OC DB Server
Hello people
I attempted to insta;; Oracle Clinical 4.5 and I have a problem that you mayhave resolved a long time back and I need some help. This is what I have done on the installation.
I need your help in centralizing my tnsnames.ora and sqlnet.ora files. I am an Oracle Clinical guy and not an Oracle Expert, hence the request.
Part_1
1. Installed Oracle 9i 9.2 database on Win2K server - W2kOCSVR
2. Installed Oracle Clinical 4.5 and created DB on W2KOCSVR.
3. Started up database and all is fine - tnsnames and sqlnet.ora
4. Each of these is on a separate partition including the OS.
Part-II
1. Installed Oracle Appl Server 9iAs 1.0.2.2.2a on another machine OCMIDTIER. This installed Oracle iSuites home and stuff.
2. Then I installed Oracle 9i developer suite - Oracle forms and reports.
3. Installed Jinitiator 1.1.8.24 on the middle tier machine.
4. Basically this is the middle tier that is a Webserver that will be linked to the Database Server in Part-I
and lastly, I will have web clients with Jinitiator and a web browser.
Requirement:
I need to centralize the TNSNAMES.ora file and the SQLNET.ora file on all the machines. How do I do this?.
I have the TNSNAMES.ora and the SQLNET.ora on DB server and it is working fine. However, I have noticed many tsnnames.ora files on the middle tier - OCMIDTIER. (I've left out the example files)
a) E:\ORACLE\806\net80\admin\tnsnames.ora
b) E:\ORACLE\806\net80\tnsapi\tnsnames.ora
c) E:\ORACLE\iSuites\hs\admin\tnsnames.ora
d) E:\ORACLE\iSuites\network\admin\tnsnames.ora
All I need to know is which if these files do I need to integrate with the Tnsnames.ora file on the DB server - W2kOCSVR and how do I go about doing this?.
Your help is appreciated. If I were to see a copy of your tnsnames.ora on the webserver (middle tier) and the sqlnet.ora, I will be able to get an idea of how this is done. Right now, I am using tnsnames.ora but once I learn how this ties up, I can move to names sever.
Thanks for your help.
CecilHi Cecil,
I got into the same issue. I copied the content from the good tnsnames.ora to tnsnames.ora on webserver and it worked fine. I copied the details of the connect string that was working fine on dbserver. i was working on W2k server. Hope this helps
Gonnagar
Maybe you are looking for
-
How do I sync music from ipod touch to computer.
I have 5.5GB of music on my ipod touch that I copied from my own cd's to an old computer that are now on my ipod touch. I want to sync the music from my ipod touch to my computer. itunes lists all the music but a message comes up when I try to list
-
Logon issues when connecting to the R/3 system via System Template
Hi All, I have created a System object for connecting to the R/3 system. the R/3 system is on ITS server. i have set the connector properties, ITS server details, User Management properties. Connector Porperties: Application Host: - , logical system
-
IPhoto 11 sharing problems.
I have a MBPro and MB, both with Lion and iPhoto 11 on a shared home network (AP Extreme). I cannot seem to get iPhoto on the two machines to recognize each other - though I used to be able to do so. Help!
-
Creating a 'dotted line' from a 'solid line'?
In Pages one can draw a line, and then choose to have it solid, or dotted, or a series-of-strokes (with a click). Is there anything comparable in Motion? I'd love to be able to turn my solid line into a 'dotted line' or 'series-of-strokes' with a sin
-
SPOILER ALERT - rookie here... ..it's getting better, but i've had some difficulties getting a good final audio output. There are 2 tracks, dialog and "background" music, and i basically mix to bring up the dialog sometimes, (while also reducing th