You can use Firewall policies to prevent DoS attacks.
A Firewall policy consists of ordered rules for permitting and denying traffic from reaching a Sensor's inspection engine and continuing on through the network. Firewall policies complement IPS policies and ignore rules to help tune a deployment. You can use Firewall policies with a Sensor in inline mode to drop or deny traffic from or to specific hosts or within a range of hosts, or traffic that meets particular requirements such as protocol type, port, application, and Windows Active Directory credentials.
Firewall policies can be created for a combination of any source IP addresses, destination IP addresses, specified CIDR blocks, destination protocol/port, by TCP/UDP port, by ICMP type, and by IP protocol for the Sensor as a whole and per individual port pair.
Firewall policies can be used to mitigate DoS attacks by creating policies specific to the nature of traffic in a network. For instance, if you are aware of what protocols are normally seen in your network, you can configure Firewall policies to drop the type of traffic that is not normally expected in your network.
Deny, Drop, Ignore, Require Authentication, Scan, Scan with Priority, Stateless Scan or Stateless Ignore response action can be set while enabling intrusion prevention matching a configured rule. When used within an enterprise, Scan can be configured from all known CIDRs.