Advanced
IDS and IPS
Signature packs in Detect or Prevent mode.
Goal
Enable intrusion detection / prevention alongside WAF policies.
Steps
- Open Advanced → IDS.
- Import or enable signature packs.
- Choose Detect (log) or Prevent (block) posture.
- Publish and monitor false positives carefully—Prevent is high impact.
Pipeline
IDS inspection runs on the Proxy after gateway auth in the middleware pipeline.
Verify
- Lab attack patterns generate IDS events in Detect.
- Prevent mode denies matching traffic.
Caution
Tune before Prevent in production. Prefer Detect + WAF Enforce as a layered start.