Why does IPS protections set to Prevent show Detect in log?

Question asked by Ilmo Anttonen on Dec 14, 2018
IPS logs show only detect on protections which have action prevent on newly activated IPS blade.

The Access control policy drops this traffic destined to the external IF of the gateway, is this the reason for detect only action? I thought IPS policy was read before the access control policy. Am I missing something here?