Chapter 7 Firewall for FortiOS 5.0 : Security policies : Interface Policies : Traffic Destined to the FortiGate unit
  
Traffic Destined to the FortiGate unit
IPS enabled in firewall policies can only inspect the traffic pass through FortiGate unit, not the traffic destined to FortiGate unit. Enabling IPS in interface-policy allows IPS to pick up any packet on the interface so it is able to inspect attacks targeting FGT.