<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>IPS Policy Between 2 Trusted Networks</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/126018/ips-policy-between-2-trusted-networks</link><description>Hello everybody I have a question? I would like to know whether IPS policy is logical between two trustworthy networks (VPN client and internal LAN)? Or do I not need to use IPS policy in this case? 
 Tanks</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: IPS Policy Between 2 Trusted Networks</title><link>https://community.sophos.com/thread/460919?ContentTypeID=1</link><pubDate>Mon, 15 Feb 2021 15:09:04 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:25574893-1e20-417b-8378-4e6ef2465ac1</guid><dc:creator>FormerMember</dc:creator><description>&lt;p&gt;If you have control over both Zones and they&amp;#39;re properly secured, Then it&amp;#39;ll be okay if you don&amp;#39;t apply any IPS policy between them. But in case if any attack originates in between trusted zones, then you won&amp;#39;t be able to detect them on the Gateway level.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: IPS Policy Between 2 Trusted Networks</title><link>https://community.sophos.com/thread/460917?ContentTypeID=1</link><pubDate>Mon, 15 Feb 2021 15:00:05 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:b375b160-a898-44d4-9755-75bef7da21b5</guid><dc:creator>Farzan Barouj</dc:creator><description>&lt;p&gt;So, you suggest me to keep the IPS policy between Trusted Zones.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: IPS Policy Between 2 Trusted Networks</title><link>https://community.sophos.com/thread/460916?ContentTypeID=1</link><pubDate>Mon, 15 Feb 2021 14:53:03 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:b454dbc0-d6d5-4690-8072-ed0c80fffc2f</guid><dc:creator>FormerMember</dc:creator><description>&lt;p&gt;Hi Farzan, This is a tricky scenario. If you&amp;#39;ve enough security measures taken to ensure the VPN zone machines are secure, You can probably get away without keeping any policy. I would suggest creating a custom IPS policy and include&amp;nbsp;the signatures according to your resources which are being accessed.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>