SANGFOR IAM v2.1 User Manual
23
The deployment is as shown in the following figure:
Under Route mode, the default gateway of all the LAN servers are directing to the LAN interface
IP of IAM gateway device, or to the layer 3 switch which then directs to IAM gateway device.
The requests for Internet access are forwarded through the NAT function or the routing function
of the IAM gateway device.
LAN interface and WAN interface should be configured with an IP address respectively that
is of different network segments.
If WAN2 interface (on the front panel of the IAM gateway device) is not used, you can define
WAN2 interface as a LAN2 or DMZ2.
If the LAN interface of the IAM gateway device is configured with 802.1Q-VLAN address,
the LAN can connect to the
TRUNK
interface of the layer 2 switch that supports VLAN, and
the IAM gateway device can forward data between different VLAN(with single-armed route),
besides, you can configure [LAN<->LAN] firewall rules. In other words, the access among
different VLAN ID (VID) can also be controlled if the LAN interface is configured with
802.1Q-VLAN address.
The [Route Mode Settings] are as shown in the figure below: