Here is what I'm trying to do: we have a edge mail appliance that is receiving bounce emails that are being detected as SMTP_RESPONSE_OVERFLOW. I'd like to be able to ignore this detection for that host, but I don't see an easy way to do this.
I'm coming to FP IPS from a Juniper perspective, where adding an exemption for a specific detection for a specific host involved a right-click and Allow on the traffic. This doesn't appear to be that easy. Do I really have to create a completely separate Access Control policy, with a completely separate Intrusion policy, just to be able to do this?