Quick Reference Guide

ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN FVS336G Reference Manual
4-20 Firewall Protection and Content Filtering
v1.0, January 2010
service to a server computer, the requested service is identified by a service or port number. This
number appears as the destination port number in the transmitted IP packets. For example, a packet
that is sent with destination port number 80 is an HTTP (Web server) request.
The service numbers for many common protocols are defined by the Internet Engineering Task
Force (IETF) and published in RFC1700, “Assigned Numbers.” Service numbers for other
applications are typically chosen from the range 1024 to 65535 by the authors of the application.
Although the VPN firewall already holds a list of many service port numbers, you are not limited
to these choices. Use the Services screen to add additional services and applications to the list for
use in defining firewall rules. The Services screen shows a list of services that you have defined, as
shown in Figure 4-11.
To define a new service, you must first determine which port number or range of numbers is used
by the application. This information can usually be determined by contacting the publisher of the
application or from user groups or newsgroups. When you have the port number information, you
can enter it on the Services screen. You can configure up to 125 custom services.
To add a custom service:
1. Select Security > Services from the menu. The Services screen is displayed.
2. In the Add Custom Services section, enter a descriptive name for the service (this name is for
your convenience).
3. Select the Layer 3 transport protocol of the service: TCP, UDP, or ICMP.
4. For TCP or UDP services, enter the first port of the range that the service uses. For ICMP
services, enter the ICMP Type number.
5. For TCP or UDP services, enter the last port of the range that the service uses. If the service
only uses a single port number, enter the same number in both fields.
Figure 4-11