Help Center/ SAP Cloud/ SAP Security White Paper/ Security Solution Mapping Table
Updated on 2022-03-04 GMT+08:00

Security Solution Mapping Table

HUAWEI CLOUD HSS has not supported Windows by Mar 5, 2018. Only Web Tamper Protection (WTP) supports Windows.

Table 1 Recommended HUAWEI CLOUD SAP security solution mapping

Requirement

Service or Product

Third-party?

Remarks

Recommended Default Configuration

Network isolation and access control

VPC–network ACL

No

Mandatory

N/A

VPC–security group

No

Mandatory

N/A

Anti-DDoS

Anti-DDoS traffic cleaning

No

Mandatory. Anti-DDoS must be performed on all EIPs and public network load balancers.

N/A

vNGFW

Hillstone vNGFW

Yes

Strongly recommended. The number and specifications of vNGFW instances are based on your service bandwidth requirements.

Two of the flagship version, working in active/standby mode

Web protection

Web application firewall

No

Mandatory. WAF protection must be performed on all public network sites.

Professional edition for N years. N refers to contract validity duration.

Direct Connect/VPN

Direct Connect

No

Mandatory. The recommended priority is Direct Connect > IPsec VPN and choose one from them.

N/A

VPN

No

Mandatory. The recommended priority is Direct Connect > IPsec VPN and choose one from them.

N/A

Bastion host

Yunanbao–Yunxiazi

Yes

Mandatory. The number and specifications of bastion hosts are based on your needs.

Two bastion hosts that support 50 assets (one for the production environment and one for the development and test environment)

Huawei dedicated bastion host

Yunanbao–Yunxiazi

Yes

Optional. The number and specifications of Huawei dedicated bastion hosts are based on your needs.

One Huawei dedicated bastion host that supports 100 assets

Security Assessment Service (SAS)

SAS–Accurate Assessment (for sites and hosts)

No

Mandatory. You can buy SAS based on the number of your sites and core hosts.

Number: 10 (sites and hosts) x N years. N refers to contract validity duration.

Website monitoring

No

Optional. You can buy the website monitoring service based on the number of your sites.

Number: 2 x N years. N refers to contract validity duration.

Host security (such as HIDS and AV)

Rising terminal security management software

Yes

Mandatory. Choose one from the four types of host security products.

Number: 10 agents

McAfee

Yes

Mandatory. Choose one from the four types of host security products.

Number: 10 agents

Server security watchdog

Yes

Mandatory. Choose one from the four types of host security products.

Number: 10 agents

HSS

No

Mandatory. Choose one from the four types of host security products.

Number: 10 agents (Linux enterprise edition) x N years. N refers to contract validity duration.

Key management

KMS

No

Optional

Based on your needs

Two-factor authentication

SecID

Yes

Optional. The specifications are based on your needs.

10 users and 10 hosts for a license