hi,
i'm trying to build a new FW policy and wondered if i just build a single custom service object with all the required ports added, i.e. TCP 80, TCP 443, TCP 8080 or create a service group and add the individual service objects.
1. would there be a difference if i used a single service object vs a service group in the FW policy?
2. what's the recommended or considered "best practice" in FGT FW policy?
3. what are the pros and cons between the two approach?
Solved! Go to Solution.
Hi John
Technically both give the same result.
But for good "convention", good logic and good management you better use service group, because there is actually no service that use those three ports.
Adding multiple ports to one service can be for cases like DNS, where you can add 53 TCP and 53 UDP in the same service.
Hope it helps.
Hi John
Technically both give the same result.
But for good "convention", good logic and good management you better use service group, because there is actually no service that use those three ports.
Adding multiple ports to one service can be for cases like DNS, where you can add 53 TCP and 53 UDP in the same service.
Hope it helps.
hi,
noted with thanks! appreciate it.
User | Count |
---|---|
2087 | |
1181 | |
770 | |
451 | |
344 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.