Hey Dan,
Sorry for the confusion. I was simply suggesting that IF you intended to create a separate policy for Spotify traffic, you can do two things.
[ol]
What you set out to do, creating the custom service with appropriate ports AND addresses, and then using that service in a policy with the appropriate source addresses and a destination address of ALL, letting the service do the IP restriction.Or, my suggestion, create the custom service with the appropriate ports but leave the addresses out of the service, and then use the appropriate source addresses while also creating and using Spotify destination addresses, letting the destination do the IP restriction.[/ol]The reason I believe #2 to be superior is because it's easier to understand when you're looking at the policy listings and will probably help avoid confusion for you or others down the road. The IP restriction doesn't show up in the tooltip for a service, so you might want to make sure to include it in the comments for that service.
You certainly can do #1 and it will work great, or you could do #3: use IP restrictions in BOTH the service and destination addresses, but that's just redundant and maybe more likely to cause confusion.
Finally, I'll say that if you weren't wanting to create a separate policy but maybe to just add the Spotify service to an existing general outbound policy, then you should do what you were planning in #1.
Thanks - Daniel