Hello what product are you talking about ? if its firepower/FTD, you apply IPS policies on your access control rules..
you want to apply IPS policy to both outbound and inbound ACLs(traffic). ofcourse if you are hosting servers on the dmz etc.. then you could have a server based (stricter) IPS policy for that traffic to block out attacks..