From 5c63cb63fa5424684ef6cd88129328f4b7b529b8 Mon Sep 17 00:00:00 2001 From: John Long Date: Thu, 27 Aug 2026 12:28:29 +0100 Subject: [PATCH 1/3] docs(onpremise): add local network validation section to connectivity guide MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Adds a "From Your Local Network" subsection under "Validate Connectivity" explaining how to test API catalog exposure directly via a browser using the internal host, port, and protocol from the Cloud Connector's virtual-to- internal system mapping — before any Cloud Connector or BTP destination is configured. --- misc/onpremise/connectivity.md | 31 +++++++++++++++++++++++++++++++ 1 file changed, 31 insertions(+) diff --git a/misc/onpremise/connectivity.md b/misc/onpremise/connectivity.md index 50526fd..6c79a74 100644 --- a/misc/onpremise/connectivity.md +++ b/misc/onpremise/connectivity.md @@ -8,6 +8,8 @@ Table of Contents - [Cloud Connector Configuration](#cloud-connector-configuration) - [SAP BTP Destination](#sap-btp-destination) - [Validate Connectivity](#validate-connectivity) + - [From SAP Business Application Studio](#from-sap-business-application-studio) + - [From Your Local Network](#from-your-local-network) - [Quick Checks](#quick-checks) - [Enable Cloud Connector Trace Logging](#enable-cloud-connector-trace-logging) - [Known Issues](#known-issues) @@ -85,6 +87,8 @@ Properties: ## Validate Connectivity +### From SAP Business Application Studio + Run the [Environment Check](../destinations/README.md#environment-check) in SAP Business Application Studio to validate the OData V2 and OData V4 catalog endpoints. The check produces an `envcheck-results.md` file with details on any failures. Address any issues in the report before proceeding to [Deployment](./deployment.md). @@ -98,6 +102,33 @@ curl -L -vs -i -H "X-CSRF-Token: Fetch" "https://.dest/sap/opu Review the `curl-catalog-output.txt` file to check for connectivity or authentication errors. +### From Your Local Network + +If you have direct network access to the ABAP system, such as when connected to the corporate VPN or on-premises network, you can validate that the API catalog endpoints are exposed before configuring the Cloud Connector or SAP BTP destination. + +Use the hostname or IP address, port, and protocol from the **Mapping Virtual to Internal System** entry in your Cloud Connector configuration. Sign in with your ABAP user credentials when prompted. + +Open the following URLs in a browser: + +**OData V2 Catalog:** + +```text +://:/sap/opu/odata/IWFND/CATALOGSERVICE;v=2?saml2=disabled +``` + +**OData V4 Catalog:** + +```text +://:/sap/opu/odata4/iwfnd/config/default/iwfnd/catalog/0001/ +``` + +Check the browser response for: + +- **XML or JSON response body**: Catalog is reachable and the user has sufficient authorizations. +- **HTTP 401 or HTTP 403**: Authentication failed or the user lacks the required roles. Check that the ICF node is active and that the user has the `SAP_BC_FNDTN_ICF` role or equivalent. +- **HTTP 404**: The catalog service is not activated. See [OData V4 Catalog Service Not Available](#odata-v4-catalog-service-not-available) or [OData V2 Catalog Returns HTTP 404](#odata-v2-catalog-returns-http-404). +- **Browser error (site can't be reached)**: The ICM port is not reachable. Confirm the host, port, and any local firewall rules. + --- ## Quick Checks From 7e0e76dec01db38d1de590d3004c4db07a332554 Mon Sep 17 00:00:00 2001 From: John Long Date: Thu, 27 Aug 2026 12:30:21 +0100 Subject: [PATCH 2/3] docs(onpremise): remove unverified ABAP role name from local validation section --- misc/onpremise/connectivity.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/misc/onpremise/connectivity.md b/misc/onpremise/connectivity.md index 6c79a74..73fb9bf 100644 --- a/misc/onpremise/connectivity.md +++ b/misc/onpremise/connectivity.md @@ -125,7 +125,7 @@ Open the following URLs in a browser: Check the browser response for: - **XML or JSON response body**: Catalog is reachable and the user has sufficient authorizations. -- **HTTP 401 or HTTP 403**: Authentication failed or the user lacks the required roles. Check that the ICF node is active and that the user has the `SAP_BC_FNDTN_ICF` role or equivalent. +- **HTTP 401 or HTTP 403**: Authentication failed or the user lacks the required roles. Check that the ICF node is active and that the user has the required authorizations. - **HTTP 404**: The catalog service is not activated. See [OData V4 Catalog Service Not Available](#odata-v4-catalog-service-not-available) or [OData V2 Catalog Returns HTTP 404](#odata-v2-catalog-returns-http-404). - **Browser error (site can't be reached)**: The ICM port is not reachable. Confirm the host, port, and any local firewall rules. From 74e4d819ded176e9bf8c50fdaffdce9a5fc1df37 Mon Sep 17 00:00:00 2001 From: John Long Date: Thu, 27 Aug 2026 12:31:07 +0100 Subject: [PATCH 3/3] docs(onpremise): add example endpoint URLs to local network validation section --- misc/onpremise/connectivity.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/misc/onpremise/connectivity.md b/misc/onpremise/connectivity.md index 73fb9bf..b1b9755 100644 --- a/misc/onpremise/connectivity.md +++ b/misc/onpremise/connectivity.md @@ -116,12 +116,16 @@ Open the following URLs in a browser: ://:/sap/opu/odata/IWFND/CATALOGSERVICE;v=2?saml2=disabled ``` +For example: `https://192.168.1.6:44300/sap/opu/odata/IWFND/CATALOGSERVICE;v=2?saml2=disabled` + **OData V4 Catalog:** ```text ://:/sap/opu/odata4/iwfnd/config/default/iwfnd/catalog/0001/ ``` +For example: `https://192.168.1.6:44300/sap/opu/odata4/iwfnd/config/default/iwfnd/catalog/0001/` + Check the browser response for: - **XML or JSON response body**: Catalog is reachable and the user has sufficient authorizations.