Below IPS Policy is applied on DNAT rule with port 80 open. During scan from WAN side with same tool no hits getting detected or triggered by IPS Policy !


Those scan IPS Rule are specific to the principle a lot of those nmap scanner works. But the internet often has own scanners, who already can skip those IPS rules. For example Shodan builds specific scanners.
__________________________________________________________________________________________________________________