Skip to Content

Need to integrate SAP Webdispatcher with Web Application Firewall

Hi Guys,

I have 2 WebDispatchers runing over the internet and the client is asking to integrate the WebDispatcher with Web Application Firewall because of my ESS/MSS application is running on the Internet.

They think using webdispatcher directly on internet is not secure so it should be configured with Web Application Firewall only.

Can anyone suggest the pros and cons of this and also how to do it?

Regards,

Musaddik Ansari.

Add comment
10|10000 characters needed characters exceeded

  • Get RSS Feed

1 Answer

  • Best Answer
    May 22 at 01:45 PM

    Dear Sapadmin,


    If I udnerstand correctly the question you want to use WEb dispatcher and Application firewall at once functioning together. I deem it is not necessary and I can not find any SAP official documentation for such integration. I deem it has no sense either.


    In case you want to use or-or techonolgy see my impressions:


    If the browser cannot access the application servers directly there can be a reverse proxy or an application firewall set in between. These restrictions do not apply to the SAP Web Dispatcher, however it also offers features such as URL filtering, HTTP request modifications, Web caching, SSL end-to-end, or re-encryption but not all the functions that a possible 3rd party LB could offer.


    By the way SAP recommends to use Web Dispatcher, since if you face any issue in web dispatcher in future, SAP can assist you. In case of third party reverse proxy SAP will be unable to assist you.


    However there are offers that are beside third party web dispatcher, see e.g. part "Possible reasons for using a third party load balancer" of the following document:


    https://wiki.scn.sap.com/wiki/x/WwtiGg


    In order to configure Application Firewall see the following documentation:


    https://www.citrix.com/content/dam/citrix/en_us/documents/solution-brief/sap-netweaver-server-with-netscaler.pdf


    Regards,
    Barnabás Paksi

    Add comment
    10|10000 characters needed characters exceeded