I am trying to get my head around IPS Policy.
Firewall I am managing was setup by another guy who is no longer in the company
There are three rules in my existing Custom policy INTERNET_IN_PROFILE , INTERNET_OUT_PROFILE, VPN_IN_PROFILE ( image attached)
![IPS-POLICY.png IPS-POLICY.png](https://community.checkpoint.com/t5/image/serverpage/image-id/26285i4BF14D97F2BCECFB/image-size/large?v=v2&px=999)
There is no protected scope applied with any of these rules but interestingly when I check the logs the first rule (Internet IN - Threat Policy) only prevents/detects IPS in the incoming traffic i.e inbound traffic mainly towards my application.
The second rule only prevents/detects IPS outbound traffic i.e traffic usually generated from my internal network.
There is no scope defined so bit confused about how this is working.