Thanks for chiming in. Just note that in the question the situation or need where we might expect traffic back from server is mentioned i.e. "To avoid all traffic coming back from IDS into ge0/0/2 ( say NIC on IDS is faulty)". Hence using a firewall filter is the right/possible way to avoid such traffic back from the server.
I agreed with Mriyaz as well, firewall filter should do the trick…I just want to bring this limitation to you, so you can be aware of it.
True egress mirroring is defined as mirroring the exact number of copies and the exact packet modifications that went out the egress switched port. Because the processor on QFX5xxx (including QFX5100, QFX5110, QFX5120, QFX5200, and QFX5210) and EX4600 (including EX4600 and EX4650) switches implements egress mirroring in the ingress pipeline, those switches do not provide accurate egress packet modifications, so egress mirrored traffic can carry incorrect VLAN tags that differ from the tags in the original traffic.
If this solves your problem, please mark this post as "Accepted Solution" so we can help others too 😄