The only sensible segments are DMZ <-> corporate client networks <-> protected infrastructure network. More than that is just to be stuborn and not more secure... ;-)
Even in these core segmentations you must still harden certain SAP internal components for which the ports must be open.
Cheers,
Julius