FarrenioFarrenio
Security architecture · 05

What do we have to open? For FCC, nothing inbound.

The first question every security team asks about an SAP monitoring tool is the right one: what do we have to open? For FCC the answer is nothing inbound.

Security reviews should be short when the architecture is simple

Monitoring tools that reach into a landscape need a way in: an open port, a firewall rule, a VPN tunnel, a service account with broad rights. Each one is a reasonable request on its own and a lasting exposure once granted.

FCC was designed the other way round from the first day. The collector agent on each SAP host connects outbound over HTTPS to the platform. Nothing listens on the SAP host, and no connection is ever opened into your landscape.

Questions a security team should ask any monitoring tool

  • Which direction do connections go?
    Inbound access to SAP hosts is the expensive kind.
  • How is each connection authenticated?
    And can one host be cut off without touching the others?
  • Who can see and do what?
    Read access, execution rights and credential access should be separate permissions.
  • What is recorded?
    Every privileged action should leave a record of who, from where and with what outcome.

How FCC answers them

Outbound only

The agent dials out over HTTPS. No new firewall rule points into your landscape.

A token per agent

Each agent carries its own token, revocable from the console at any time.

Granular roles

Role-based, per-action permissions, with customers isolated from each other by design.

Audit trail and encryption

Privileged actions are recorded, and stored SSH credentials are encrypted at rest.

FCC does not ask for a way into your network. That was a design goal, not a feature added later.

Go deeper

Common questions

Does FCC need a VPN into our network?
No. The collector connects outbound over HTTPS, so no VPN or inbound rule is needed.
What happens if we want to disconnect a host?
Revoke that agent's token in the console. The other hosts are unaffected.

Bring your security team into the evaluation early.

We will walk them through the connection model, the role model and the audit trail. FCC is in Beta.

"SAP" and SAP product names are used descriptively. Farrenio Cloud Control is a Farrenio product and implies no partnership with or endorsement by SAP.