Hi Michael, I would suggest you to use the "Internet Service Database"
objects for this. These are dynamic objects maintained by Fortinet
including IPs / Ports for specific services (contract required). So you
would create two firewall policies - one...