Policy rules within an Advanced IP Defense profile define how the firewall enforces security policies based on IP attributes and direct-to-IP detection. Each policy rule specifies match criteria using real-time IP attributes, logical operators to combine conditions, and actions to take when traffic matches the rule.