You can create a custom service with a specific range of ports and apply
that to the policy allowing traffic. config firewall service custom edit
set protocol TCP/UDP set tcp-portrange
set udp-portrange nextend Find below KB
describing the steps:
...