Skip to main content
sviatoslav_redko
New Member
October 3, 2018
Question

NAT limitation and SAP HANA protection design

  • October 3, 2018
  • 0 replies
  • 2222 views

Hello,

We do design for Fortigate SAP HANA solution and want to use Fortigate in NAT mode between corporate network and SAP HANA network. Also we suggested to put SAP HANA network behind the NAT (which implemented on FG). If SAP HANA has many inbound connection (for example, 5 000), and FG has SNAT limitation in 10 000, we will reach 1/2 NAT size, and if each connection will use 2 tcp ports we will reach SNAT maximum walue. FG model - 1200D.

So the questions is:

does anyone have the same experience and put SAP behind the NAT? Did you have any issues with NAT size?

is it good idea/practice to put SAP HANA behind the NAT and hide it from customer at all? Does anyone has different ideas?

 

Thank you for ideas and help,

Slava.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!