In Server & Gateway mode the firewall is automatically installed and configured.
No user configuration is required.
The appropriate ports are opened (and/or closed) when the server is initially configured using the Configure server panel and also when changes are made using server manager.
You don't have to directly configure firewall (iptables) rules unless you have a particular reason ie you wish to do something that is not catered for in the server manager or configuration screens.
This concept applies to all the settings in a sme server, make the changes you require in server manager and the behind the scenes conf files are updated automatically.
Makes it very easy to use.
Of course it is totally configurable using command line if that's what you need to do, but you should do these type of changes using custom templates, keeping in mind the way the templating system works to update the conf files.
Regs
Ray