But your firewall already blocks everything from outside in.Don't you trust your internal devices? I do.Then as I wrote in that other German thread - there's blocklists and Crowdsec.
What I tried to explain and what you obviously did not get is that the provided IDS/IPS rules from which you can choose have errors of first and second degree.That means: 1) there may be things they do not catch and 2) there will be false alarms that may cripple your experience because these rules would block legitimate traffic if IPS is enabled.The first order problems are not of your concern, since if you did not enable IPS at all, these unmitigated attacks would get unnoticed as well. However: do not expect perfect protection from an IPS.Second order problems will be your problem when you enable IPS and then return here and ask "why does this not work"?In order to avoid this, you will have to see which false alarms occur in your specific situation, i.e. with the services you actually use. We do not know, so either you invest the time or pay someone to do it for you. There is no "one size fits all" or "automagical" approach here. You will see that if you search the forum for questions about how suricata blocks legitimate traffic. And every single update may bring new rules along that then block something new - sometimes correctly, sometimes not.If you neither want to invest the time yourself nor pay someone to do it, you are facing the question: "Do I want to risk crippling my internet connection for a mechanism I do not fully understand and which cannot reach 100% efficiency anyway?"With Crowdsec, you may be getting the most of what you obviously want: You relay your decicions to the crowd, hoping that they have a similar use pattern as you and that the same rules are applicable for you, too.
Second order problems will be your problem when you enable IPS and then return here and ask "why does this not work"?...You will see that if you search the forum for questions about how suricata blocks legitimate traffic. And every single update may bring new rules along that then block something new - sometimes correctly, sometimes not.