How Google Cloud Helps SAP Admins Create Scalable, Secure Networks

6656
Of your peers have already read this article.
3:00 Minutes
The most insightful time you'll spend today!
SAP forms the critical backbone of thousands of enterprises, supporting critical business functions such as finance, supply chain, warehouse management, and more. Google Cloud provides a highly scalable and resilient infrastructure to run such workloads and offers tools, such as Smart Analytics and Machine Learning that can accelerate your organization’s digital transformation.
In fact, a recent study by Forrester found that running SAP on Google Cloud can generate a 160% return on investment and a payback period of six months or less, thanks to legacy infrastructure cost savings, downtime avoidance, and productivity improvements.
How you deploy your SAP systems across your network has a tremendous impact on its availability, resilience, and performance. In addition to separate production and high-availability (HA) environments, SAP deployments typically include sandbox, development, quality assurance (QA), and disaster recovery environments as well.
Because most of the Google network is virtual, SAP administrators can easily design complex landscapes that suit your organization’s SAP deployment and organizational structure while also meeting security and operational requirements.
As you get started with SAP on Google Cloud, you’ll need to decide how to configure your networking to ensure the availability and performance of various SAP systems. Here’s a look at your options.
VPC and shared VPC
A virtual private cloud (VPC) is a secure, isolated private network hosted within Google Cloud. VPCs are global in Google Cloud, so a single VPC can span multiple regions without communicating across the public internet. Similarly, subnets can span across zones within a region. A zone represents a single failure domain, so typical SAP deployments place production and HA systems in different zones to ensure resiliency. Google Cloud simplifies this type of deployment, because subnets containing both production and HA systems can span multiple zones.
This capability also simplifies SAP clustering, since the cluster’s virtual IP (VIP) address can be in the same range as those of the production and HA machines. This configuration shields the floating IP using Google internal load balancers and is applicable to HA clustering of the application layer (ASCS and ERS) and the HANA database layer (HANA Primary and Secondary).

Shared VPCs are a feature unique to Google Cloud that allows an organization to connect resources from multiple projects to a common VPC network. This lets them communicate with each other securely and efficiently using internal IPs. You can also centrally control the network for all SAP projects (service) from the Host project while using firewalls to inspect communication between compute engines in the same subnet, and between those in different subnets. (Best practice is to limit the communication between these systems to only the required ports — typically via SAP remote function call (RFC) communication at Layer 4.)
When designing your network, start with a host project containing one or more Shared VPC networks. You can attach additional service projects to a host project, which allows them to participate in the Shared VPC. It’s common practice to have multiple service projects operated and administered by various departments or teams in your organization.
Depending on your needs, you can deploy SAP on a single Shared VPC or multiple ones. The two scenarios differ in terms of network control, SAP environment isolation, and network inspection. Let’s look more closely at these differences.
Scenario 1: Deploying SAP on a single Shared VPC
If you require only a single network inspection, deploying SAP on a single Shared VPC has the advantage of simplicity and reduces administrative overhead.
- Network control: The Shared VPC serves as the network hub, allowing central network management based on identity access management (IAM) roles for the network team(s) in both production and non-production environments.
- SAP environment isolation: You can create projects and subnets for each SAP environment. Projects help group resources together for finer IAM control and billing visibility, while subnets provide network isolation for individual SAP environments. In service projects, compute engines can communicate by default; however, you can adopt simple firewall rules to block communication between compute engines within a subnet or in separate subnets.
- Network inspection: Use Google Cloud firewalls to allow only the required ports for communication between SAP systems. Leverage network tags and service accounts to define granular control for both north-south and east-west traffic.

Scenario 2: Multiple Shared VPCs for SAP deployment
In scenarios requiring additional network inspections, you can create multiple Shared VPCs, typically one per environment. Use peering between these Shared VPCs to enable RFC communication among the SAP development, QA, and production systems.
- Network isolation: Multiple Shared VPCs are completely isolated from each other except via specific ports opened in Google Cloud firewalls. This allows additional East-West traffic inspection by a Network Virtual Appliance (NVA) within a Google Cloud network.
- Network control:As the number of Shared VPCs increases, activities such as peering and firewall policies also increase. This diminishes the central network control that Shared VPCs offer, so the network team should plan to manage the policies in each VPC separately.

Hybrid scenarios – for example, one Shared VPC for the production environment and one Shared VPC for all non-production systems — are also possible. This arrangement allows network inspection between production and non-production systems, and limits the number of central network administration layers to two.
Configuring the networking environment for multiple SAP systems can be a complex process. Thanks to Google Cloud’s Shared Virtual Clouds and other tools, SAP administrators can create scalable, secure networks that provide logic, resilience, and visibility to their cloud deployments.Learn more about these networking capabilities and our full offerings for SAP customers.
Italian Utility Company Deploys its SAP Workloads on Google Cloud to Meet Sustainability Goals

3259
Of your peers have already read this article.
2:00 Minutes
The most insightful time you'll spend today!
With more than 2.5 million customers, Italian utility company A2A is committed to delivering electricity, gas, clean water, and waste collection every day. More recently, the company made another significant commitment: To incorporate the principles of the “circular economy” into its way of doing business — part of the UN 2030 Agenda’s Sustainable-Development Goals — all while also aiming to double its client base by 2030. Growing rapidly but sustainably requires operating as efficiently as possible at every level of the organization, from operating smart meters to generating accurate demand projections. That’s why A2A chose to deploy its SAP S/4HANA ERP and the SAP BW/4HANA data warehouse on Google Cloud.
Roadblocks to innovation
Instead of a linear consumption model that starts with raw materials and ends with use and disposal, the circular economy is a continuous cycle that emphasizes repair, recycling, and the creation of materials rather than their disposal. To take an example from A2A’s own success story: The company keeps 99.7 percent of collected waste out of landfills.1 Of the UN’s sustainability goals, A2A is committing to the three most relevant to its industries:
- Ensuring availability and sustainable management of water and sanitation for all
- Ensuring sustainable consumption and production patterns
- Protecting, restoring, and promoting sustainable use of terrestrial ecosystems
Achieving A2A’s sustainability and customer-first strategies requires high scalability, rapid data ingestion, and rich, accurate analytics. None of this could be reliably supported with the company’s legacy on-premises SAP and Data Warehouse, especially given A2A’s projected growth and the increasing complexity of the data landscape, including IoT deployments and energy market liberalization.
Provisioning data infrastructure was also slow and complex. Simply adding a new metric could require increasing capacity by an order of magnitude. And analytical and transactional data lived in siloes, which created a fragmented and out-of-date view of each customer across sales and customer support teams. A2A’s fragmented data also made it difficult to take proactive action when changing priorities or processes required shifting focus from one data source to another.
With a data warehouse that refreshed only once every 24 hours, simple processes such as responding to a customer calling because their power has been cut off due to an unpaid bill became cumbersome.
Scalability was also a concern. With the on-premises solution, A2A needed to define the budget for its data warehouse over a two-year timeframe, but the rollout of new electricity meters — each sending data every 10 minutes — across Italy made those data requirements hard to predict.
The move to the cloud: From monolith to microservices
The move has been a giant step forward in A2A’s goal of meeting its data-driven, customer-centric strategy. In deploying its SAP systems to Google Cloud, A2A can take advantage of a highly flexible hybrid environment and powerful data management and analytics. It can replicate data from Salesforce, SAP, and other systems in BigQuery, which operates as a data lake with Google Cloud SQL, connected directly to Google Analytics and Google Ads for data-driven customer service, decision-making, and marketing.
“From BigQuery we can feed relevant information directly to the people who need it. Our customer operators work on Salesforce, so we use an OData protocol to embed real-time data in that platform. Elsewhere, we present the information through a dashboard, or with a BI component delivering one-page reports.” —Vito Martino, Head of CRM, Marketing and Sales B2C & B2B, A2A
By running SAP on Google Cloud, A2A can also count on an infrastructure platform that provides:
- Scalability. The robust data architecture on Google Cloud adapts to shifting and increasing demands without compromising on speed or availability, so A2A doesn’t have to worry about over- or under-provisioning as the rollout of smart meters proceeds.
- Speed. The new A2A data solution refreshes every five minutes instead of 24 hours, so the company can respond to its customers’ needs without delays. Customer operators working in Salesforce now receive real-time data from Google BigQuery so that, when a customer calls, operators can see accurate information in seconds. They can now offer value-added services and sustainable options tailored to the customer’s needs, from energy consumption to their preferred method of communication.
- Availability. With microservices orchestrated by Google Kubernetes Engine, the team can update the solution through continuous integration and delivery (CI/CD), eliminating the need for downtime when changes are required.
- Security and control. The A2A IT team uses Google Kubernetes Engine to orchestrate clusters of instances on Google Compute Engine, with Google Cloud Load Balancing and backups on Google Cloud Persistent Disk. Google Cloud Anthos ensures operational consistency across on-premises and cloud platforms.
Ready to grow the sustainable way
By moving to Google Cloud — the industry’s cleanest cloud, with zero net emissions — A2A is ready to grow quickly while locking down the efficiency it will need to meet its ambitious sustainability goals. “To bring sustainable utilities to market, we need to be both responsive to our customers and responsive to the internal needs of A2A,” explains Davide Rizzo, Head of IT Governance and Strategy at A2A. “Understanding what customers need in detail means we can improve their services and reduce their environmental impact at the same time.”
Learn more about the ways Google Cloud can transform your organization’s SAP solutions with scalability, speed, and advanced analytics capabilities.
1. Circular Economy: one of the four founding pillars of A2A’s 2030 sustainability policy | Drupal
Highmark & Google’s Secure-by-design Technique to Bring the Living Health Solution to Life

6546
Of your peers have already read this article.
3:30 Minutes
The most insightful time you'll spend today!
In an industry as highly regulated as healthcare, building a single secure and compliant application that tracks patient care and appointments at a clinic requires a great deal of planning from development and security teams. So, imagine what it would be like to build a solution that includes almost everything related to a patient’s healthcare, including insurance and billing. That’s what Highmark Health (Highmark)—a U.S. health and wellness organization that provides millions of customers with health insurance plans, a physician and hospital network, and a diverse portfolio of businesses–decided to do.
Highmark is developing a solution called Living Health to re-imagine healthcare delivery, and it is using Google Cloud and the Google Cloud Professional Services Organization (PSO) to build and maintain the innovation platform supporting this forward thinking experience. Considering all the personal information that different parties like insurers, specialists, billers and coders, clinics, and hospitals share, Highmark must build security and compliance into every part of the solution.
In this blog, we look at how Highmark Health and Google are using a technique called “secure-by-design” to address the security, privacy, and compliance aspects of bringing Living Health to life.
Secure-by-design: Preventive care for development
In healthcare, preventing an illness or condition is the ideal outcome. Preventive care often involves early intervention—a course of ideas and actions to ward off illness, permanent injury, and so on. Interestingly, when developing a groundbreaking delivery model like Living Health, it’s a good idea to take the same approach to security, privacy, and compliance.
That’s why Highmark’s security and technology teams worked with their Google Cloud PSO team to implement secure-by-design for every step of design, development, and operations. Security is built into the entire development process rather than waiting until after implementation to reactively secure the platform or remediate security gaps.
It’s analogous to choosing the right brakes for a car before it rolls off the assembly line instead of having an inspector shut down production because the car failed its safety tests. The key aspect of secure-by-design is an underlying application architecture created from foundational building blocks that sit on top of a secure cloud infrastructure. Secure-by-design works to ensure that these building blocks are secure and compliant before moving on to development.
The entire approach requires security, development, and cloud teams to work together with other stakeholders. Most importantly, it requires a cloud partner, cloud services, and a cloud infrastructure that can support it.
Finding the right cloud and services for secure-by-design
Highmark chose Google Cloud because of its leadership in analytics, infrastructure services, and platform as a service. In addition, Google Cloud has made strategic investments in healthcare interoperability and innovation, which was another key reason Highmark decided to work with Google. As a result, Highmark felt that Google Cloud and the Google Cloud PSO were best suited for delivering on the vision of Living Health—its security and its outcomes.
“Google takes security more seriously than the other providers we considered, which is very important to an organization like us. Cloud applications and infrastructure for healthcare must be secure and compliant,” explains Highmark Vice President and Chief Information Security Officer, Omar Khawaja.
Forming a foundation for security and compliance
How does security-by-design with services work? It starts with the creation and securing of the foundational platform, allowing teams to harden and enforce specified security controls. It’s a collaborative process that starts with input from cross-functional teams—not just technology teams—using terms they understand, so that everyone has a stake in the design.
A strong data governance and protection program classifies and segments workloads based on risk and sensitivity. Teams build multiple layers of defense into the foundational layers to mitigate against key industry risks. Google managed services such as VPC Service Controls help prevent unauthorized access. Automated controls such as those in Data Loss Prevention help teams quickly classify data and identify and respond to potential sources of data risk. Automation capabilities help ensure that security policies are enforced.
After the foundational work is done, it’s time to assess and apply security controls to the different building blocks, which are Google Cloud services such as Google Kubernetes Engine, Google Compute Engine, and Google Cloud Storage. The goal is to make sure that these and similar building blocks, or any combination of them, do not introduce additional risks and to ensure any identified risks are remediated or mitigated.
Enabling use cases, step by step
After the foundational security is established, the security-by-design program enables the Google Cloud services that developers then use to build use cases that form Living Health. The service enablement approach allows Highmark to address complexity by providing the controls most relevant for each individual service.
For each service, the teams begin by determining the risks and the controls that can reduce them. The next step is enforcing preventive and detective controls across various tools. After validation, technical teams can be granted an authorization to operate, also called an ATO. An ATO authorizes the service for development in a use case.
For use cases with greater data sensitivity, the Highmark teams validate the recommended security controls with an external trust assessor, who uses the HITRUST Common Security Framework, which maps to certifications and compliance such as HIPAA, NIST, GDPR, and more. A certification process follows that can take anywhere from a few weeks to a few months. In addition to certification, there is ongoing monitoring of the environment for events, behavior, control effectiveness, and control lapses or any deviation from the controls.
The approach simplifies compliance for developers by abstracting compliance requirements away. The process provides developers a set of security requirements written in the language of the cloud, rather than in the language of compliance, providing more prescriptive guidance as they build solutions. Through the secure-by-design program, the Highmark technology and security teams, Google, the business, and the third-party trust assessor all contribute to a secure foundation for any architectural design with enabled Google Cloud services as building blocks.
Beating the learning curve
Thanks to the Living Health project, the Highmark technology and security teams are trying new methods. They are exploring new tools for building secure applications in the cloud. They are paying close attention to processes and the use case steps and, when necessary, aligning different teams to execute. Because everyone is working together collaboratively toward a shared goal, teams are delivering more things on time and with predictability, which has reduced volatility and surprises.
The secrets to success: Bringing everyone to the table early and with humility
Together, Highmark and Google Cloud PSO have created over 24 secure-by-design building blocks by bringing everyone to the table early and relying on thoughtful, honest communication. Input for the architecture design produced for Highmark came from privacy teams, legal teams, security teams, and the teams that are building the applications. And that degree of collaboration ultimately leads to a much better product because everyone has a shared sense of responsibility and ownership of what was built.
Delivering a highly complex solution like Living Health takes significant, more purposeful communication and execution. It is also important to be honest and humble. The security, technology, and Google teams have learned to admit when something isn’t working and to ask for help or ideas for a solution. The teams are also able to accept that they don’t have all the answers, and that they need to figure out solutions by experimenting. Khawaja puts it simply, “That level of humility has been really important and enabled us to have the successes that we’ve had. And hopefully that’ll be something that we continue to retain in our DNA.”
Qlik and Google Cloud Combo: Extending Integration of SAP Data on BigQuery

5461
Of your peers have already read this article.
2:00 Minutes
The most insightful time you'll spend today!
If your organization is one of the 52% of SAP customers whose top analytics pain point is data integration1, Google Cloud has got you covered. By working with partners like Qlik, we are expanding our integration options and bringing real-time replication capability for SAP to BigQuery.
Integrated data for accelerated insights
BigQuery—our fully managed, enterprise data warehouse that can scale up to petabytes on demand and execute queries in seconds—allows SAP customers to consolidate enterprise data silos and confidently derive more use and value from their data. Customers can accelerate and simplify the delivery of SAP data on BigQuery with the latest Qlik Data Integration platform offering for Google Cloud which allows data integration using an automated, near real-time data pipeline through Qlik Replicate, whether data originates from legacy SAP environments, SAP HANA, or SAP application servers. Additionally, Qlik Compose for Data Warehouses can be used to easily generate and automate logical data models from SAP directly in BigQuery freeing up more time for data analysts to leverage advanced built-in capabilities such as BigQuery ML to derive greater value and insights using standard SQL without the need for advanced programming expertise.
Delivering faster results with real-time
Traditional extract-transform-load (ETL) solutions operate on a batch basis, pulling data sets from SAP daily, hourly, or every minute. These tools often require manual mapping of multiple data fields so that data flows accurately. Given SAP’s highly complex table relationships, in which a single transaction can result in multiple changes, this can be a time consuming and tedious process. ETL can also increase the burden on your SAP systems.
Qlik Replicate simplifies this with its intuitive user interface where you can set up real-time data replication between SAP and BigQuery, eliminating the need for manual coding. And, to prevent system overhead, as soon as a new transaction is entered into SAP, the resulting data is replicated into BigQuery in a process known as change data capture (CDC) from SAP’s log layer. This means that data transfer can benefit from high performance with minimal impact on the source system’s resources. Read our latest white paper to learn how to extract SAP data into BigQuery leveraging Qlik Replicate.
Solution expertise for all core SAP workloads
It doesn’t matter what database your SAP system runs on, Qlik Replicate supports all core SAP systems. It automates real-time data replication and decodes SAP’s complex, application-specific data structures into formats that flow smoothly into BigQuery. This ensures that anyone who depends on data analytics has the most current and relevant SAP data they need. For its robust solution capabilities Qlik has received a new “SAP on Google Cloud Expertise” designation for supporting:
- Fast onboarding and accelerated replication of SAP data into Google Cloud
- Real-time and continuous data replication from SAP applications to BigQuery
- Support for all core SAP modules and a broad set of data sources
- Automated data integration, which cuts resource requirements for initial delivery and ongoing maintenance
Proven customer results
Many SAP customers have experienced the benefits of leveraging Qlik alongside BigQuery for data analytics and AI at scale, including German luxury department store chain Breuninger. In order to meet its customers’ growing and changing expectations,Breuninger needed to accelerate its time to insight from data sources across a highly dispersed landscape of on-premises databases and systems, including SAP. The company uses Qlik Replicate to feed corporate data from modules in its SAP system into BigQuery and integrate its varying on-premises databases with the Google Cloud environment. This has yielded game-changing, real-time customer insights for the retailer.
What could your business do with faster, more integrated insights? Learn more about BigQuery for SAP customers and also how Qlik and Google Cloud can help you modernize and automate data integration and analytics.
5880
Of your peers have already watched this video.
1:30 Minutes
The most insightful time you'll spend today!
FFF Enterprises See 80% Improvements in Speed at Lower Cost by Moving SAP Data to Google Cloud
FFF Enterprises, a pharmaceutical distributor of lifesaving biopharma products, vaccines and plasma products deployed SAP on Google Cloud to leverage its ability to scale server demands, reduce costs and improve speed and performance. Learn how the migration helps FFF empower healthcare to care!
1401
Of your peers have already watched this video.
2:30 Minutes
The most insightful time you'll spend today!
Greenovation: Adani and Google Cloud Join Forces for a Sustainable and Data-Driven India
As the biggest renewable energy developer, Adani aims to put India on the green map. Working with the world’s cleanest cloud inspired the organisation to solve their own efficiency issues, and better manage their facilities across the country to lower their carbon footprint.
- For more on Adani, visit: https://www.adani.com/
- For more on Google Cloud Customer Stories, visit: https://cloud.google.com/customers
- For more on how our customers across the region are solving with Google Cloud, visit: APAC YouTube Channel: @GoogleCloudAPAC
- Follow Google Cloud India on Facebook for more updates: https://www.facebook.com/GoogleCloudIN
More Relevant Stories for Your Company
WPP Innovates with the Cloud
Unlocking the Power of Data and Creativity withthe Cloud: The WPP Story

Google Unveils New Cloud Region in Delhi NCR to Power India’s Digitization
In the past year, Google has worked to surface timely and reliable health information, amplify public health campaigns, and help nonprofits get urgent support to Indians in need. Now, we are continuing to focus on helping India’s businesses accelerate their digital transformation, deepening our commitment to India’s digitization and economic recovery.

The Tech Tightrope: How the U.S. State & Local Agencies Strive to Balance between Innovation and Budget
State and local government (SLG) agencies are reeling from a combination of unbudgeted COVID-related expenses and reduced tax revenue caused by unemployment and business closures. Any way you look at it, the situation is challenging. To understand how SLG agencies are coping, Google Cloud collaborated with MeriTalk to survey 200

Titanium: A Robust Foundation for Workload-optimized Cloud Computing
Google Cloud is built on world-class technical infrastructure that supports services that are loved and relied on by billions of people across the globe: Google Search, YouTube, Gmail, Google Maps and more. A core tenet at Google Cloud is to leverage Google’s experience building and operating highly available and highly







