Help us enhance your Sophos Community experience. Share your thoughts in our Sophos Community survey.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Traffic processing flow (order of operations). IPS before Firewall?

Found a post from over 10 years ago, so thought I'd ask and get a more up-to-date reply!

I get alerts from the IPS saying it blocked an attack. I add the IP (if it's the same one repeatedly) to Network Protection/Firewall to drop from that IP, Any service, Any Destination. I even put the country in the Country Blocking list (From).

I still get IPS notifications from this IP.

Is IPS processing done before the Firewall processing?

Thanks, James.



This thread was automatically locked due to age.