Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
dirkdigs
New Contributor

using internet service definitions in my firewall policies

hello i cannot figure out how to enable this? i only see "Services" when creating firewall policies. 

 

i am using forti os 5.6.5 . 

 

do i need to enable it somehow or is this a 6.x feature only ?

8 REPLIES 8
Toshi_Esumi
SuperUser
SuperUser

Custom services can be created under Policy&Objects->Services. Hit the "Create New" button at the top.

dirkdigs

i don't want to create a custom service .

 

i want to use the existing internet service database entries 

http://help.fortinet.com/...l-internet-service.htm

Toshi_Esumi

Internet-services database entries are used as Destinations, not Services. Because those are resolved to IP addresses instead of ports.

dirkdigs

so i could not use 'Google-Web' as an example if my intention was to create a single "Internet Allowed Out" Policy because it would only allow traffic to specific destinations. 

 

is this correct?

Toshi_Esumi

You can specify 'Google-Web' as Destination and allow access to it.

dirkdigs

then i am limiting which destination IP address i can access which i do not want .

 

I want to allow all destination IP .

AKrause

dirkdigs wrote:

I want to allow all destination IP .

You don't need Internet Service Database in that case. Just add a legacy policy with dst: all.

 

 

James_G

Add it as a destination, not a service
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors