In some environments, the firewall may drop traffic on an IDP rule that references a custom attack group, even when the matched signature is not part of that custom attack group.
This behavior can be seen after changing an IDP rule action from no-action to drop-packets or recommended. It is most commonly observed in deployments where multiple LSYS instances use the same IDP configuration, including the same custom attack group name.
You may observe one or more of the following:
Use a unique custom attack group name for each LSYS. This workaround prevents unintended signature matching across LSYS instances and stops the firewall from incorrectly dropping traffic due to IDP policy evaluation.