The intrusion prevention function is enabled on the FW to protect intranet servers and clients against intrusions.
As shown in Figure 1, the FW is deployed at the intranet boarder. The intrusion prevention function is enabled on the FW to detect the traffic from the Internet to intranet resources, such as servers and computers. If an intrusion is detected, the FW blocks the intrusion. Otherwise, the FW permits the connection.
As shown in Figure 2, the FW is deployed at the intranet boarder. If the web pages accessed by intranet users contain any malicious codes, the FW blocks the web pages. Otherwise, the FW permits the access.
Besides the two scenarios, the FW detects and processes traffic between different areas within the intranet.