> Source: [sk122102](https://support.checkpoint.com/results/sk/sk122102)

# sk122102 - Traffic is dropped by IPS blade, while the protection is set to Inactive or Detect

| Property | Value |
|----------|-------|
| Solution ID | sk122102 |
| Date Created | 2017-12-31 |
| Last Modified | 2023-05-01 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * IPS Protection was defined to either Accept/Detect/Inactive, yet the action of IPS blade is different than the desired action.
* IPS blade might be configured on Detect Mode, yet some traffic will be dropped by specific protections (Prevent).

## Cause

Starting in R80.10, IPS protections were divided into two main types:

1. **Core protections**- protections which are included in the product and are assigned per gateway. They are part of the Access Control policy.
2. **ThreatCloud protections** - updated from the Check Point cloud. These protections are part of the Threat Prevention policy.

Core Protections and ThreatCloud Protections are not sharing the same Profile.

In other words, IPS will share 2 profiles, one for each type of protections (Core and ThreatCloud).

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
