Troubleshooting - Complete Reference
Overview
This guide covers common issues and solutions for SAP BTP Connectivity components.
HTTP Error Codes
405 Method Not Allowed
Cause: Using HTTPS instead of HTTP for Connectivity Proxy
Solution:
- Use
http://protocol with port20003 - The proxy handles TLS termination internally
// Wrong
const proxyUrl = 'https://connectivity-proxy:20003';
// Correct
const proxyUrl = 'http://connectivity-proxy:20003';407 Proxy Authentication Required
Cause: Missing or invalid proxy authorization header
Solution: Add Proxy-Authorization header with Bearer token
const response = await axios.get(targetUrl, {
proxy: {
host: 'connectivity-proxy',
port: 20003,
protocol: 'http'
},
headers: {
'Proxy-Authorization': `Bearer ${accessToken}`
}
});503 Service Unavailable
Causes:
- Cloud Connector offline
- Location ID mismatch
- On-premise system unreachable
Solutions:
- Check Cloud Connector status
- Verify
CloudConnectorLocationIdmatches Cloud Connector configuration - Check network connectivity from Cloud Connector to target system
# Check Cloud Connector status
# Windows
sc query "SAP Cloud Connector"
# Linux
systemctl status scc_daemon502 Bad Gateway
Cause: Target system returned error or connection failed
Solution: Check Cloud Connector logs and on-premise system availability
504 Gateway Timeout
Cause: Target system took too long to respond
Solution:
- Increase timeout settings
- Check target system performance
- Verify network latency
Cloud Connector Issues
Cannot Connect to Subaccount
Symptoms:
- Red status indicator
- "Connection failed" message
Checklist:
- Verify region URL is correct
- Check firewall allows outbound HTTPS (port 443)
- Verify subaccount credentials
- Check if proxy is required
Proxy Configuration:
Administration UI > Cloud To On-Premise > HTTPS Proxy
Host: <proxy-host>
Port: <proxy-port>Access Denied to Resource
Symptoms:
- HTTP 403 or 404 for specific paths
- "Not exposed" errors
Checklist:
- Verify system mapping exists
- Check virtual host/port match destination
- Verify resource path is exposed
- Check access policy allows path
Access Control Verification:
Cloud Connector > Access Control > <Backend>
Check:
- System mapping exists
- Resource paths are listed
- Policy: "Path and All Sub-Paths" if neededCertificate Errors
Symptoms:
- "Certificate expired" warnings
- Connection failures with SSL errors
Solutions:
Renew Subaccount Certificate:
Cloud Connector > Subaccount > Dashboard > Refresh CertificateRenew System Certificate:
Configuration > On Premise > System Certificate > RenewHigh Availability Issues
Symptoms:
- Shadow doesn't sync
- Both instances active (split-brain)
Solutions:
Shadow Not Syncing:
- Verify Master is accessible from Shadow
- Check Master hostname/port in Shadow configuration
- Verify firewall allows connection
Split-Brain Recovery:
- Stop one instance
- Clear state on stopped instance
- Restart as Shadow
- Verify sync completes
Performance Issues
Symptoms:
- Slow response times
- High CPU/memory usage
Solutions:
Check Hardware Metrics:
Cloud Connector > Monitoring > Hardware MetricsIncrease JVM Heap:
# Edit scc_daemon configuration
# Linux: /opt/sap/scc/scc_daemon
JAVA_OPTS="-Xmx4g"Review Access Control:
- Remove unnecessary system mappings
- Use specific paths instead of wildcards
Destination Service Issues
Destination Not Found
Symptoms:
- HTTP 404 from Destination Service
- "Destination not found" error
Checklist:
- Verify destination name spelling (case-sensitive)
- Check destination visibility level (subaccount vs instance)
- Verify service instance binding
# List destinations via API
curl -X GET "${destinationUri}/destination-configuration/v1/subaccountDestinations" \
-H "Authorization: Bearer ${token}"Authentication Token Not Retrieved
Symptoms:
authTokensarray empty in response- OAuth flow failures
Checklist:
- Verify OAuth credentials
- Check token service URL
- Verify scopes are correct
- Check token service is reachable
Debug Token Retrieval:
# Test token service directly
curl -X POST "${tokenServiceURL}" \
-H "Content-Type: application/x-www-form-urlencoded" \
-d "grant_type=client_credentials" \
--data-urlencode "client_id=${clientId}" \
--data-urlencode "client_secret=${clientSecret}" \
-vPrincipal Propagation Failures
Symptoms:
- User identity not propagated
- X.509 certificate not generated
Checklist:
- User JWT provided in request
- Cloud Connector trust configuration
- Subject pattern configured
- On-premise system trusts Cloud Connector
Required Headers for Principal Propagation:
headers: {
'Proxy-Authorization': `Bearer ${accessToken}`,
'SAP-Connectivity-Authentication': `Bearer ${userJwt}`
}Connectivity Proxy Issues
Pod Startup Failures
Symptoms:
- CrashLoopBackOff
- Init container failures
Check Logs:
kubectl logs statefulset/connectivity-proxy -n <namespace>
kubectl describe pod connectivity-proxy-0 -n <namespace>Common Causes:
- Missing service credentials secret
- Invalid credentials
- Network connectivity issues
Connection Refused
Symptoms:
ECONNREFUSEDerrors- Cannot reach proxy
Solutions:
- Verify proxy is running
- Check service exists
- Verify port configuration
# Check service
kubectl get svc connectivity-proxy -n <namespace>
# Check endpoints
kubectl get endpoints connectivity-proxy -n <namespace>Log Level Adjustment
# Enable debug logging
kubectl exec connectivity-proxy-0 -n <namespace> -it -- change-log-level DEBUG
# List loggers
kubectl exec connectivity-proxy-0 -n <namespace> -it -- list-loggers
# Reset to INFO
kubectl exec connectivity-proxy-0 -n <namespace> -it -- change-log-level INFOTransparent Proxy Issues
Destination Custom Resource Not Working
Symptoms:
- Service not created
- Destination unreachable
Check Resource Status:
kubectl get destinations.destination.connectivity.api.sap -n <namespace>
kubectl describe destination my-destination -n <namespace>Common Conditions:
| Condition | Meaning |
|---|---|
Available |
Destination is ready |
NotReady |
Configuration issue |
Error |
Check events for details |
Error Response Headers
Check these headers in failed responses:
| Header | Content |
|---|---|
x-error-message |
Error description |
x-error-origin |
Component that failed |
x-request-id |
Correlation ID for logs |
# Include headers in curl
curl -v http://my-destination.namespace/api/resource 2>&1 | grep "x-error"Service Name Conflicts
Symptom: Destination not accessible
Cause: Kubernetes Service with same name exists
Solution: Rename destination or service to avoid conflict
Network Issues
Firewall Blocking
Required Outbound Connections:
| Source | Destination | Port | Protocol |
|---|---|---|---|
| Cloud Connector | SAP BTP Region | 443 | HTTPS |
| Connectivity Proxy | Connectivity Service | 443 | HTTPS |
| Application | Destination Service | 443 | HTTPS |
Proxy Server Issues
Cloud Connector Behind Corporate Proxy:
Configuration > Cloud To On-Premise > HTTPS ProxyNote: Only basic authentication supported (not NTLM)
Log Locations
Cloud Connector
Windows:
C:\SAP\scc\log\Linux:
/opt/sap/scc/log/Kubernetes Proxies
# Real-time logs
kubectl logs -f statefulset/connectivity-proxy -n <namespace>
kubectl logs -f deployment/transparent-proxy -n <namespace>
# Previous container logs
kubectl logs --previous <pod-name> -n <namespace>Diagnostic Commands
Cloud Connector
# Check version
cat /opt/sap/scc/config/version.txt
# Check connectivity
curl -v https://connectivitycertsigning.<region>.hana.ondemand.com/Kubernetes
# Pod status
kubectl get pods -n <namespace> -l app=connectivity-proxy
# Resource usage
kubectl top pods -n <namespace>
# Events
kubectl get events -n <namespace> --sort-by='.lastTimestamp'
# Network policies
kubectl get networkpolicies -n <namespace>Support Information
SAP Support Components
| Component | Support Component | Notes |
|---|---|---|
| Cloud Connector | BC-MID-SCC | Multi-cloud middleware |
| Destination Service | BC-CP-DEST | CF variant: BC-CP-DEST-CF |
| Connectivity Proxy | BC-CP-CON | CF variant: BC-CP-CON-CF |
| Transparent Proxy | BC-CP-CON / BC-CP-DEST | No separate component |
Information to Collect
- Component version
- Error messages and codes
- Timestamps of issues
- Relevant log excerpts
- Configuration (sanitized)
- Steps to reproduce
Documentation Links
- Cloud Connector FAQ: https://help.sap.com/docs/connectivity/sap-btp-connectivity-cf/frequently-asked-questions
- Connectivity Proxy Troubleshooting: https://help.sap.com/docs/connectivity/sap-btp-connectivity-cf/troubleshooting-connectivity-proxy
- Common Issues: https://help.sap.com/docs/connectivity/sap-btp-connectivity-cf/common-issues-and-solutions
Last Updated: 2025-11-22