Customers may observe unexpected behavior in their monitoring systems after applying Intrusion Detection and Prevention (IDP) on security policies. Specifically:
This behavior may appear inconsistent with expectations, as higher-severity threats are typically assumed to be blocked by default.
IDP actions are not applied solely based on severity level (Critical, Medium, Low).
Instead, the enforcement behavior depends on the recommended action defined for each individual attack signature by Juniper Threat Labs.
Each IDP signature has a predefined recommended action such as:
As a result:
This is expected behavior when IDP is configured to follow recommended actions.
To verify or understand why a specific signature is being allowed or dropped:
The recommended action determines how the traffic is handled when IDP is applied using default or recommended settings.
You can verify the recommended action for each individual IDP signature at the following page:
https://www.juniper.net/us/en/threatlabs/ips-signatures.html
NOTE:
If stricter enforcement is required, customers can:
Changes should be carefully evaluated to avoid false positives and unintended traffic drops.