I think, but am not 100% sure, that this allows Astaro to not run all the IPS rules for every packet that goes through. For instance, if you have a web server on only one machine, it makes sense to only scan packets going to that machine for http exploits and not packets to every machine on your network.