Hi experts,
From just a security standpoint, what additional benefits SAP API Management brings on top of SAP Cloud Connector for exposing on premise backend SAP Gateway services for further consumption by UI5 apps deployed in SAP BTP?
I am just interested in security topics (SAP APIM brings other benefits as for example API Discovery, Caching, or Analytics but these are out of the scope for this discussion). The idea is trying to understand if there is any additional benefit in the security space if we the service calls go UI5 --> API M --> SAP CC --> SAP GW instead of UI5 --> SAP CC --> SAP GW.
SAP Cloud Connector creates a TLS tunnel between SAP BTP and the on-premise landscape and given that in the data exchanges the host of the SAP Cloud Connector is not used, no DDoS can occur. So we are wondering what additional security can be added in SAP APIM that is not already provided in SAP Cloud Connector.
Many thanks!
C.
Request clarification before answering.
Dear Charles,
I would not add the API Managment in between the UI and the service you consume from the backend via the Cloud Connector as long as the UI can only be accessed by authenticated users. With API managment inbetween you add another layer of complexity and latency in the loop.
But if you have a e.g. public registration form that uses a backend service, you have to protect this API from DoS attacks.
Best regards
Gregor
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
| User | Count |
|---|---|
| 5 | |
| 4 | |
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.