ShieldGate Docs

Advanced

IDS and IPS

Signature packs in Detect or Prevent mode.

Goal

Enable intrusion detection / prevention alongside WAF policies.

Steps

  1. Open Advanced → IDS.
  2. Import or enable signature packs.
  3. Choose Detect (log) or Prevent (block) posture.
  4. Publish and monitor false positives carefully—Prevent is high impact.

Pipeline

IDS inspection runs on the Proxy after gateway auth in the middleware pipeline.

Verify

  • Lab attack patterns generate IDS events in Detect.
  • Prevent mode denies matching traffic.

Caution

Tune before Prevent in production. Prefer Detect + WAF Enforce as a layered start.