Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
johnlloyd_13
Contributor II

Create a Service with all TCP/UDP Ports Vs Service Group

hi,

i'm trying to build a new FW policy and wondered if i just build a single custom service object with all the required ports added, i.e. TCP 80, TCP 443, TCP 8080 or create a service group and add the individual service objects.

1. would there be a difference if i used a single service object vs a service group in the FW policy?

2. what's the recommended or considered "best practice" in FGT FW policy?

3. what are the pros and cons between the two approach?

 

1 Solution
AEK
SuperUser
SuperUser

Hi John

Technically both give the same result.

But for good "convention", good logic and good management you better use service group, because there is actually no service that use those three ports.

Adding multiple ports to one service can be for cases like DNS, where you can add 53 TCP and 53 UDP in the same service.

Hope it helps.

AEK

View solution in original post

AEK
2 REPLIES 2
AEK
SuperUser
SuperUser

Hi John

Technically both give the same result.

But for good "convention", good logic and good management you better use service group, because there is actually no service that use those three ports.

Adding multiple ports to one service can be for cases like DNS, where you can add 53 TCP and 53 UDP in the same service.

Hope it helps.

AEK
AEK
johnlloyd_13
Contributor II

hi,

noted with thanks! appreciate it.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors