Chapter 15 Unified Threat Management for FortiOS 5.0 : Intrusion protection : IPS examples : Configuring a Fortinet Security Processing module : Network configuration
  
Network configuration
The Example Corporation network needs minimal changes to incorporate the ASM-CE4. Interface amc-sw1/1 of the ASM-CE4 is connected to the Internet and interface amc‑sw1/1 is connected to the web server.
Since the main office network is connected to port2 and the Internet is connected to port1, a switch is installed to allow both port1 and amc-sw1/1 to be connected to the Internet.
Figure 310: The FortiGate-620B network configuration
The switch used to connect port1 and amc-sw1/1 to the Internet must be able to handle any SYN flood, all of the legitimate traffic to the web site, and all of the traffic to and from the Example Corporation internal network. If the switch can not handle the bandwidth, or if the connection to the service provider can not provide the required bandwidth, traffic will be lost.