User guide
Configuring Firewall Settings
100 WatchGuard Firebox X Edge
9 Repeat the last three steps until you have a list of all the ports
and protocols that this service uses.
You can have more than one port and more than one protocol in a
custom service.
More ports and protocols make the service more dangerous. Limit the
service to only the ports and protocols that are necessary.
Filtering a service for outgoing traffic
These steps restrict outgoing traffic through the Firebox. Refer to
“Filtering traffic for incoming services” on page 94 for information
on filtering incoming traffic.
1 From the Outgoing Filter drop-down list, select Allow or Deny.
2 To allow any computers on the trusted or optional network to
send traffic to any location on the external network using this
service, skip the subsequent instructions and click Submit at the
bottom of the page.
3 To put a limit on the computers on the trusted or optional
network that can send traffic to the external network using this
service, use the drop-down list below the From box to select
Host IP Address, Network IP Address, or Host Range.
Network IP addresses must be entered in “slash” notation (also known as
Classless Inter Domain Routing or CIDR notation). For more information
on entering IP addresses in slash notation, see this FAQ: http://
www.watchguard.com/support/advancedfaqs/general_slash.asp.
4 In the address text boxes, type the host or network IP address,
or type the range of IP addresses that identify the computers on
the trusted or optional network that can use this service to send
traffic to the external network.
5 Click Add. The From box shows the IP addresses you added.
Repeat the last three steps until all of the From address information for
this custom service is set. The From box can have more than one entry.
6 To put a limit on the computers on the external network that
can be connected to using this service, use the drop-down list
below the To box to select Host IP Address, Network IP
Address, or Host Range.
7 In the address text boxes, type the host or network IP address,
or type the range of IP addresses that identify the computers on
the external network that internal computers can connect to
using this service.