An IPS sensor must be explicitly applied to the same firewall policy that references the SSL/SSH inspection profile. After the SSL/SSH proxy decrypted the traffic, the flow or proxy engine passes the decrypted payload to the IPS sensor, which matches it against configured intrusion signatures and enforces the defined action. Policy-level binding is essential: without both the SSL/SSH profile and the IPS sensor on the same policy, the FortiGate cannot inspect the decrypted content for threats.