SANGFOR IAM v2.1 User Manual
30
[Default Gateway]: Directs to the next hop interface IP of the bridge.
Under Multi-Bridge mode, you have to configure [Default Gateway] for each bridging
direction. [Default gateway] configures the default route of each bridge that is directing to the
gateway.
Under Bridge mode, gateway of the LAN PC needs no other change, but remains directing to
the original gateway, in other words, LAN PC directs to the LAN interface IP address of the
front-end device.
Under Bridge mode, the data for Internet access should be ensured to pass through IAM
gateway device, that is, the LAN user must not bypass the IAM gateway device and follow
the physical line of the original gateway to get access to the Internet.
As to data traversing, please ensure the WAN zone connects to the front-end routing device
and the LAN zone connects to the LAN switch. These two connections cannot be mixed up.
The data for Internet access transmitted from LAN zone to WAN zone can be monitored and
controlled.
“Transparency” of bridge-mode IAM gateway device is achieved at the data link layer (the
second layer of OSI), interfaces of the device are being bridged; the data of layer 2 and the
layers above can be traversed. This feature of the IAM gateway device enables the DHCP
service and the IP/MAC binding (of the original gateway) work.
NAT function is unavailable in Bridge mode.
Under Bridge mode, VPN module on the local IAM gateway device is unavailable.
If you want to enable the anti-virus function, email filter, etc., or if you want to have the URL
library, application identification library and virus library automatically updated, you need to
configure the [Bridge IP List], [Default Gateway] and [DNS], and make sure the IAM
gateway device itself to get access to the external network (you can implement “ping” to
check the availability of the external network).
If you want to enable the WEB authentication, ingress rule or other functions that need to be
redirected to the IAM gateway device and there are several LAN segments, you must add a
corresponding route, directing to the routing device.
If the computers of layer 2 switch have multiple network segments (instead of VLAN), the
gateway should also have IP addresses of multiple segments. If so, and you want to enable
the functions that need to be redirected to the IAM gateway device, such as anti-virus
function, email filter, ingress rule, WEB authentication, etc., the IP addresses of these