as far as I understood it this feature lets you select your http and other servers and for those servers only the related Intrusion Protection rules will be applied. Only HTTP related rules will be used for the given HTTP servers and only SMTP related rules for your SMTP servers. This meassure increases Intrusion Protection performance dramatically.
I think, but am not 100% sure, that this allows Astaro to not run all the IPS rules for every packet that goes through. For instance, if you have a web server on only one machine, it makes sense to only scan packets going to that machine for http exploits and not packets to every machine on your network.