SANGFOR IAM v2.1 User Manual
34
Click the <Next> button to continue the next step, configuring [Excluded IP List], as shown
below:
[Excluded IP List]: Access data requested by these excluded IP addressed will not be recorded.
Bypass mode deployment supposes that there is a HUB or a switch with mirror port. If the
switch has no mirror port, please connect a HUB to the front end of the switch.
Under Bypass mode, <View Flow Ranking> and <View Connection Ranking> are
unavailable.
Under Bypass mode, TCP control is fulfilled by sending „reset‟ packets through the DMZ
interface. Therefore, to achieve TCP control, all the „reset‟ packets sent through the DMZ
interface must be ensured to be received by the PC and the server of the public network.
Many functions are not available in bypass mode, such as VPN, DHCP and Ingress rule, etc.
Bypass-mode IAM gateway mode mainly plays a monitor role; control functions are not as
complete as those of Route mode or Bridge mode, for it can only restrict some TCP
connections, such as URL filtering, keyword filtering, email filtering, etc. No UDP
connection control can be done, such as P2P software, QQ login, etc.
3.4.4.
Single-Arm Mode
Single-arm-mode deployment takes the IAM gateway device as a proxy. IAM gateway device can
fulfill monitoring and controlling, and can avoid disconnection of the users with the Internet. The
IAM gateway device is connected to the HUB or the mirror port of the switch, monitoring the
overall local area network. Single-arm mode requires no change on user‟s networking and plays