SANGFOR IAM v2.1 User Manual
82
Chapter 5
Firewall
[Firewall] covers configurations of [Firewall Rules], [NAT Rules], [Anti-DoS] and [ARP
Protection], as shown below:
5.1.
Firewall Rule
[Firewall Rule] configures the specific settings of data packet access. IAM gateway device allows
you to configure the filtering rules for data transmission between [LAN<->DMZ],
[DMZ<->WAN], [WAN<->LAN], [LAN<->LAN], [DMZ<->DMZ], [VPN<->WAN] and
[VPN<->LAN].
5.1.1.
LAN <-> DMZ
[LAN <-> DMZ] configures the rule for data transmission fulfilled between LAN interface and
DMZ interface. The service can be all the services of certain protocol or a user-defined service.
For example, to have the communication between the LAN interface and DMZ interface available,
you have to enable all the TCP, UDP and ICMP services and have them available for both
directions, LAN > DMZ and DMZ > LAN. By default, all the TCP, UDP, ICMP services are
accessible for [LAN->DMZ]; however, if the rule is not enabled, the [Status] displayed in the
[Firewall Rule List] is [Disable], as shown below: