I am trying to get my head around IPS Policy.
Firewall I am managing was setup by another guy who is no longer in the company
There are three rules in my existing Custom policy INTERNET_IN_PROFILE , INTERNET_OUT_PROFILE, VPN_IN_PROFILE ( image attached)
There is no protected scope applied with any of these rules but interestingly when I check the logs the first rule (Internet IN - Threat Policy) only prevents/detects IPS in the incoming traffic i.e inbound traffic mainly towards my application.
The second rule only prevents/detects IPS outbound traffic i.e traffic usually generated from my internal network.
There is no scope defined so bit confused about how this is working.