Hi,
You shouldn' t open a any rule inbound to internal services / servers, this is not the purpose of the compliance test. Compliance scans for all security standards, ISO 27001, PCI DSS, FCA, DPA, CESG, etc, etc are intended to test the current state security and to find any inbound connections.
You shouldn' t be opening any traffic for the purposes of the scan, this will go down as a vulnerability.
The requirement is to leave the inbound traffic profiles exactly as they are but to disable IPS for any inbound services for the source IP range of the external scanners.
You would likely have to create a duplicate rule for each inbound rule, with a second rule (labelled an audit rule) placed above each inbound rule and configured with the source range of the external scanner and with any UTM functions disabled.
Mark
Infosec Partners