Hi Piotr
I would keep both active as a defense in deep strategy, even if by mistake you should except something on CWAF, you still have another layer of security that could be protecting your assets. To ensure maximum security and system performance, maintain a multi-layered defense architecture. Keep your IPS active downstream from your WAF, and do not create complete traffic exemptions. And of course, don't forget to permit only traffic from Imperva's proxies to your origin servers. Keep in mind that the IPS would probably see only encrypted traffic, unless you decrypt the traffic from the proxies to the asset. If you need any further information, just reach me anytime.
By the way, major security compliance frameworks mandate a Defense-in-Depth approach. Maintaining both systems ensures we fulfill the distinct network and application layer requirements for PCI-DSS, ISO 27001:2022, and SOC 2.
------------------------------
Martin Morey
Sales Engineer
Thales CSP (AppSec).
------------------------------