SAP on AWS
Hybrid Connectivity: On-Premises to AWS
16 flashcards · answers and spaced-repetition review in the KnowCard app
You need to connect a remote branch office network (not individual laptops) to AWS over an encrypted tunnel, and you want redundancy. Which of the four AWS VPN options fits, and which one is the trap?
An SAP org refuses any internet-path connectivity to AWS. Given that a VPN is encrypted and quick to set up, why do most of them still choose Direct Connect instead?
You have one VPN/Direct Connect on-prem link and a growing number of VPCs that all need to reach it and each other. Why does stitching them with VPC peering break down, and what fixes it?
Two requirements land separately: (a) traffic must be encrypted in transit, (b) traffic must never touch the public internet. One is satisfied by VPN, the other by Direct Connect. Which is which, and why can't you assume one gives you both?
You need a Direct Connect link sized above 10 Gbps. Does it matter whether you go dedicated or hosted (through a delivery partner), and why?
A global company wants its multiple data centers and offices to talk to each other through AWS, not over the internet. Someone proposes a mesh of site-to-site VPNs. Which Direct Connect feature is the cleaner fit, and what's the key distinction?
Your footprint is expanding into a second AWS region. Can a single Transit Gateway cover both, and what does its OSI layer tell you about what it can route?
Your on-premise data center isn't near any AWS Region. Does that mean Direct Connect can only reach a nearby Region, and where do you actually plug in?
Your team wants to terminate a VPN vendor and feature set you already run on-premise inside AWS, rather than use an AWS-managed VPN. Which AWS VPN option fits, and what changes about who supports it?
A freshly created VPC with a private CIDR is invisible from your on-premise network. What has to be attached before on-premise systems can reach it, and how is that channel secured?
During a phased migration your SAP BW is already on AWS but the SAP ERP/S4HANA source is still on-premise, connected by RFC. Is that split landscape supported, and why is RFC tolerant of the cloud boundary?
A data center exit forces you off your old site, but one system legally or technically can't move into an AWS Region. What placement keeps latency low without a full migration into AWS?
A replication link needs sustained throughput above 1.25 Gbps. What's the ceiling on a single Site-to-Site VPN, how do you push past it, and where does Direct Connect's range sit by comparison?
You've heard Direct Connect isn't encrypted out of the box, yet a security policy demands encryption on the wire. What native encryption can Direct Connect use, and at which OSI layer versus the VPN approach?
Choosing the migration network path: a VPN is faster to stand up, so why is Direct Connect still 'highly recommended' for SAP migrations, and when is Site-to-Site VPN actually acceptable?
You're placing SAProuter on AWS so it can reach both your SAP systems inside AWS and the on-premise landscape plus the SAP support backbone. Which connectivity does each side use?
Start learning today
Free to start — download the app or use it in your browser.
