182 Fortinet Inc.
Services Firewall configuration
Services

Use services to control the types of communication accepted or denied by the firewall.

You can add any of the predefined services to a policy. You can also create your own

custom services and add services to service groups.

This section describes:

Predefined services

Providing access to custom services

Grouping services

Predefined services

The FortiGate predefined firewall services are listed in Table6. You can add these

services to any policy.

Table 6: FortiGate predefined services
Service name Description Protocol Port
ANY Match connections on any port. A connection
that uses any of the predefined services is
allowed through the firewall.
all all
GRE Generic Routing Encapsulation. A protocol that
allows an arbitrary network protocol to be
transmitted over any other arbitrary network
protocol, by encapsulating the packets of the
protocol within GRE packets.
47
AH Authentication Header. AH provides source
host authentication and data integrity, but not
secrecy. This protocol is used for
authentication by IPSec remote gateways set
to aggressive mode.
51
ESP Encapsulating Security Payload. This service is
used by manual key and AutoIKE VPN tunnels
for communicating encrypted data. AutoIKE
key VPN tunnels use ESP after establishing the
tunnel using IKE.
50
AOL AOL instant messenger protocol. tcp 5190-5194
BGP Border Gateway Protocol routing protocol.
BGP is an interior/exterior routing protocol.
tcp 179
DHCP-Relay Dynamic Host Configuration Protocol (DHCP)
allocates network addresses and delivers
configuration parameters from DHCP servers
to hosts.
udp 67
DNS Domain name service for translating domain
names into IP addresses.
tcp 53
udp 53
FINGER A network service that provides information
about users.
tcp 79
FTP FTP service for transferring files. tcp 21
GOPHER Gopher communication service. Gopher
organizes and displays Internet server contents
as a hierarchically structured list of files.
tcp 70