After detecting an anomaly, the IPS device will perform inspection in real-time for every packet traveling in the network. If it finds any packet suspicious, the IPS can block the suspicious user or IP address from accessing the network or application, terminate its TCP session, reconfigure or reprogram the firewall, or replace or remove malicious content if it remains after the attack.