Hello Bruno,
Yes, this setting is perfectly possible using Blockbit VPN NG module.
Unlike the classic SSL VPN, VPN NG operates based on the Hubs concept. You can create multiples Independent hubs, where each works as a separate VPN instance.
To meet your scenarios, you would do the following:
1. Create two distinct Hubs: One called "Admin" and another "SAP Support".
2. Set Tunnel Networks:
In the "Admin" Hub, you set the IP pool to 172.16.0.0/24.
In the "SAP Support" Hub, you set the pool to 172. 17.0.0/24.
3. Segment to Authentication and Access:
Associate each Hub with your respective user group (e.g. IT Group for Hub Admin, SAP Group for SAP Hub).
Firewall rules can be created based on the virtual interface of each Hub or defined IP ranges, ensuring that SAP personnel do not have access to the administration network and vice versa.
This way, you get the complete segmentation of external access you need.