Alibaba Cloud overview
Alibaba Cloud SAP NetWeaver overview
Alibaba Cloud is built on top of global infrastructure, offering a variety of Infrastructure as a Service (IaaS) products and services. Customers can use Alibaba Cloud services in different regions around the world. Before you run SAP NetWeaver on Alibaba Cloud, you must thoroughly understand the following foundational knowledge:
Alibaba Cloud ECS
Alibaba Cloud Elastic Compute Service (ECS) is a web service that provides scalable computing capacity in the cloud. Simple web service APIs allow you to easily obtain and configure computing resources. As your computing needs change, you can quickly scale up or down your computing capacity, and you only pay for the actual usage.
Alibaba Cloud Elastic Block Storage device
Alibaba Cloud Elastic Block Storage devices provide persistent block-level storage volumes for Alibaba Cloud ECS instances running on the Alibaba Cloud platform. Disk volumes offer consistency and low-latency performance, meeting the needs of your workload operations. You can use Elastic Block Storage devices to increase or decrease your usage within minutes, and all of this is available at a low cost, billed based on actual usage.
OSS
Alibaba Cloud Object Storage Service (OSS) is an easy-to-use service that allows you to store, back up, and archive large amounts of data in the cloud. OSS serves as an encrypted central repository, enabling secure access to files from around the world. With availability guaranteed up to 99.9999%, OSS is an ideal choice for global teams and international project management.
VPC
Virtual Private Cloud (VPC) allows you to create an isolated network environment. You can select IP address ranges, divide networks, and configure route tables and gateways.
SAP NetWeaver and Alibaba Cloud services work together to provide customers with an integrated enterprise application and infrastructure capability in a specific manner.
The SAP NetWeaver system and database components utilize Alibaba Cloud ECS instance storage services and VPC services.
The SAP Host Agent/SAPOSCOL can be deployed as part of the standard SAP NetWeaver installation and is capable of invoking the monitoring agent component provided by Alibaba Cloud.
The Alibaba Cloud ECS Metrics Collector is a monitoring agent that can collect the required CPU, memory, disk, and network monitoring data, and it can provide these monitoring metrics for use by SAP applications.
Two-layer architecture
In this architecture, all components run on a single ECS instance. The ECS instance is attached with three disks, each of which plays a specific role.
System disk: contains the operating system and paging files of the ECS instance.
Data disk 1: contains the SAP NetWeaver installation and configuration files and the database installation and configuration files.
Data disk 2: contains database data files that are used to maintain data consistency. Note: Data disk 2 must be an SSD or ESSD to ensure database performance.
Data disk 3: contains database log files that are used to maintain data consistency. Note: Data disk 3 must be an SSD or ESSD to ensure database performance.
For more information about the architecture of SAP HANA, see SAP HANA deployment guide.
For more information about the two-layer deployment of SAP HANA, visit 1953429 - SAP HANA and SAP NetWeaver AS ABAP on one Server.
Three-layer architecture (SAP NetWeaver application server scale-out)
To process higher workloads, SAP supports a scale-out architecture that uses multiple application servers on demand.
In a scale-out configuration, each node must access the same shared file system. For Linux, use the "Network File System" (NFS) as the file sharing system for the NetWeaver binaries/configuration files disk of the central system (/sapmnt/[SID], where [SID] is the system ID). For more information, refer to the SAP documentation.
In this architecture, the SAP NetWeaver system can distribute workloads to multiple NetWeaver application servers (AS) hosted on multiple ECS instances. All NetWeaver AS nodes share the same database, which is hosted on a separate ECS instance.
All NetWeaver AS nodes are installed and access a shared file system where SAP NetWeaver binaries and configuration files are hosted. For Linux, use the "Network File System" (NFS) as the file sharing system for the NetWeaver binaries/configuration files disk of the central system (/sapmnt/[SID], where [SID] is the system ID). For more information, refer to the SAP documentation.
High availability
For more information about high-availability deployment of SAP applications on Alibaba Cloud, see Best practices for high-availability deployment of SAP S/4HANA in the same zone.
Alibaba Cloud ECS
ECS instance type
Alibaba Cloud ECS provides a variety of instance types (virtual machine specifications) to deploy SAP solutions. Each instance type provides different CPU, memory, and I/O capabilities. You can run SAP applications only on ECS instances that are certified by SAP. For more information about SAP-certified instance types for SAP NetWeaver, visit 2552731 - SAP Applications on Alibaba Cloud: Supported Products and IaaS VM types
For more information about ECS instance types, visit the Alibaba Cloud official website.
Image
When you create an ECS instance, you use an image that contains a pre-installed basic operating system. Alibaba Cloud works with operating system partners to provide you with the latest and optimized operating system images. You can select a method to specify an image for your ECS instance.
Public image
The operating system license fees for public images are included in the pricing of the ECS instance. You do not need to provide your own operating system license. The following list describes the operating systems required for SAP NetWeaver, which are available in the public image list:
Linux
SUSE Linux Enterprise Server 12 SP2 (SLES 12) or higher
Red Hat Enterprise Linux 7.4 (RHEL 7) or higher
Windows
Microsoft Windows Server 2012 R2, Microsoft Windows Server 2016, and Microsoft Windows Server 2019
For more information about the supported operating systems, visit 2552731 - SAP Applications on Alibaba Cloud: Supported Products and IaaS VM types.
Region and zone
The Alibaba Cloud infrastructure is built around regions and zones. A region refers to a specific physical location on Earth, and in most cases, a service is available in multiple regions. A zone consists of one or more distributed data centers, each with redundant power, network, and connectivity capabilities, and located in separate facilities. These zones provide you with the ability to run production environment applications and databases with higher availability, fault tolerance, and scalability compared to a single data center. Alibaba Cloud operates 29 zones across 14 regions globally.
VPC
VPC allows you to create a dedicated and isolated network environment within Alibaba Cloud, where you can run IaaS resources in a self-defined virtual network. With VPC, you can define a virtual network topology that closely resembles your traditional on-premises operations network. You can also establish a connection between your enterprise data center and the Alibaba Cloud VPC, leveraging Alibaba Cloud as an extension of your enterprise data center.
Deploy an ECS instance
You can deploy your ECS instances on the Alibaba Cloud platform by using standard Alibaba Cloud methods, which include the ECS console and REST API. The ECS console is a web UI of the cloud platform console. For more information, see the following topic:
For more information and step-by-step instructions on how to deploy SAP NetWeaver on ECS, see Alibaba Cloud SAP NetWeaver Implementation Guide.
Access an ECS instance
For Linux-based ECS instances, users can use the SSH feature and access the ECS instances by using SSH-based tools such as PuTTY. For example, you can use PuTTY to access an ECS instance from a jump server.
For Windows-based ECS instances, you can access the ECS through Remote Desktop Protocol (RDP) if your public IP address can access the ECS instance.
Database
For Alibaba Cloud SAP NetWeaver, you can use SAP HANA.
SAP HANA
SAP HANA is only supported for SUSE Linux Enterprise Server. For more information about supported ECS instance types and operating systems, see SAP HANA deployment guide.
For more information about SAP HANA, see the SAP HANA operation guide and SAP documentation.
For more information about SAP HANA specification guidelines and recommendations, visit the SAP official website.
Database backup and recovery
Most SAP NetWeaver systems are used for mission-critical workloads. Therefore, customers must have a data backup and recovery plan in place to ensure that their systems and databases can be restored in the event of a worst-case scenario.
Storage
By default, each ECS instance comes with a small system disk (either an efficient disk or an SSD) that contains the operating system. You can add additional data disks and mount them to the ECS instance to serve as storage for different components of your system.
Elastic Block Storage device
Alibaba Cloud Elastic Block Storage devices provide persistent block-level storage volumes that can be used with Alibaba Cloud ECS instances. You can choose from different types of disks based on your business requirements:
For data reliability, leveraging the advantages of Alibaba Cloud distributed storage technology with a triple-redundant storage system, all three types of cloud disks can implement 99.9999999% data integrity.
For SAP HANA databases, we recommend that you use SSDs or ESSDs.
OSS
Alibaba Cloud OSS is an object storage solution for files of any type or format. It offers virtually unlimited storage space, and you do not need to worry about capacity limits or scaling issues.
A common practice is to use OSS for storing archived or infrequently accessed files.
Network and security
Security group
A security group acts as a virtual firewall, which is used to set network access control for one or more ECS instances. When you create an instance, you must select a security group. You can also create security group rules to control the outbound and inbound network access for all ECS instances within the security group.
SSH key pair
Alibaba Cloud provides two authentication methods for remotely logging on to ECS instances:
Password logon: The standard authentication method of using the administrator password. This method is applicable to both Windows instances and Linux instances.
SSH key pair logon: This method applies only to Linux instances. If you use a Linux operating system, we recommend that you select this authentication method to protect your ECS instances.
An SSH key pair is a pair of keys generated by a cryptographic algorithm: one is publicly accessible, called the public key, and the other is retained by you, called the private key.
By default, Alibaba Cloud creates a 2048-bit RSA key pair. You can also import the public key of a key pair generated by other key pair generation tools. For more information, see Overview.
If you place the public key in a Linux instance, you can use the private key to log on to this instance by running the SSH command or by using related tools from your local computer or another instance without entering a password.
Router configuration
When you create a VPC on Alibaba Cloud, the system automatically creates a router and a route table after the VPC is created. You cannot directly create or delete them. After the VPC is deleted, the router and route table are automatically deleted. You can add route entries to a route table to route network traffic.
Each entry in the route table is used to direct the direction of network traffic. When you create a VPC, the system automatically adds a route entry whose destination CIDR block is 100.64.0.0/10. You can add custom route entries for your VPC.
If an ECS instance that does not have an external IP address in a VPC needs to access the Internet, a NAT gateway is required.
Bastionhost
A bastion host provides an external entry point into the VPC containing private virtual machines. This host serves as a single point of defense or audit and can be started or stopped to enable or disable inbound SSH communication from the external network.
By connecting to the bastion host first, SSH access to virtual machines without external IP addresses can be achieved.
When you use a bastion host, you first log on to the bastion host, and then connect to the target ECS instance by using an SSH-based tool such as PuTTY.
NAT gateway
If an ECS instance is created within a VPC and does not have an external IP address assigned, it cannot directly connect to external services.
To allow the ECS instance to access the Internet, you can set up and configure a NAT gateway. NAT Gateway can route traffic on behalf of any ECS instance within the VPC. Each VPC must have one NAT gateway.
When you deploy an SAP solution, you must configure a NAT gateway that contains SNAT for the VPC. For more information about the configuration, see the "Implementation guide" topic.
If you want to access your SAP system from the Internet, we recommend that you use a NAT gateway.
VPN gateway
You can securely connect your existing data center and Alibaba Cloud VPC in Alibaba Cloud through a VPN gateway and VPN connection (using IPSec). The traffic transmission between the two networks is encrypted by one VPN gateway and then decrypted by the other VPN gateway. This protects your data transmission over the external network. For more information, visit the Alibaba Cloud official website.
If you only want to access your SAP system from your data center or office LAN, we recommend that you use a VPN gateway to connect your local data center and office LAN to the Alibaba Cloud VPC.
Security documentation
The following resources can help you learn more about the SAP landscape in Alibaba Cloud from a security and compliance perspective:
SAP NetWeaver monitoring and support
SAP applications in the cloud environment run on a guest operating system (Guest OS) installed in a virtualized environment. The SAP Host Agent collects all the information required for SAP monitoring and makes it available to SAP NetWeaver local monitoring and Solution Manager for analysis and display. Customers or SAP technical support personnel can access SAP tools via the SAP transaction code ST06, either through the local ABAP monitoring system or through Solution Manager (for managed systems running in Alibaba Cloud).
In addition, Alibaba Cloud and SAP have collaborated to build a monitoring agent for SAP NetWeaver running on Alibaba Cloud: the ECS Metrics Collector. The ECS Metrics Collector is responsible for collecting information on configuration and resource (CPU, memory, disk, network) utilization from the underlying Alibaba Cloud infrastructure and virtualization platform, and providing it to the SAP Host Agent.
For more information and step-by-step instructions on how to install the ECS Metrics Collector, see the ECS Metrics Collector for SAP deployment guide.
License
SAP license
To run SAP on Alibaba Cloud, you must have a self-owned license (BYOL).
For more information about SAP licenses, contact SAP.
Linux license
You can select one method to obtain a SUSE Linux license in Alibaba Cloud.
Pay-as-you-go licensing mode: Alibaba Cloud provides SLES 12 for SAP and SLES 15 for SAP, with the cost of the SLES subscription included in the ECS instance price.
BYOL mode: Customers can purchase their own SLES licenses and import the SLES operating system as a custom image.
Installation media
To replicate the SAP installation media to an ECS instance, you can use one of the following methods:
Download directly from the SAP Service Marketplace to the ECS instance. Connect to the SAP Service Marketplace from your ECS instance and download the required installation media. This method is probably the fastest way to obtain SAP installation media in Alibaba Cloud, because the connection speed between the ECS instance and the Internet is very fast. You can create a dedicated ECS instance to download and store the SAP installation media.
Copy the media from your network to the ECS instance. If you have downloaded the required SAP installation media to a location on your network, you can copy the media directly from your network to the ECS instance.
SAP Router and Solution Manager
This section describes the relevant options for SAP Solution Manager and SAP router when running SAP solutions on Alibaba Cloud.
Hybrid architecture: Deploy some SAP solutions in the cloud and some in data centers.
If you use Alibaba Cloud as an extension of your IT infrastructure, you can use the existing SAP Solution Manager system and SAP router running in your data center to manage the SAP system running in the Alibaba Cloud VPC.
Pure Alibaba Cloud architecture
When you set up an SAP environment in Alibaba Cloud, you need to set up an SAP Solution Manager system and SAP router and connect to the SAP support network, just like any infrastructure.
Follow these guidelines when setting up the SAP router and SAP support network connections:
The instance on which the SAP router software is to be installed must be launched into a public subnet of the Alibaba Cloud VPC and assigned an elastic IP address (EIP).
A specific security group must be created for the SAP router instance, with the necessary rules configured to allow the required inbound and outbound access to the SAP support network.
You must use a secure network communication (SNC) type of Internet connection. For more information, visit https://support.sap.com/en/tools/connectivity-tools/remote-support.html.