We have a rule set up to use the TIF thusly:

We're getting alerts from Bad Folks
trying to hit our outside IP, but that's happening all the time -- a good portion of the reason one doesn't put an IPS outside of the firewall. Does anyone have any good Use Case examples for the TIF? We're looking at crafting a rule that alerts us if any internal systems go to a TIF destination, but otherwise... ?