12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Viewing the predefined service list<br />

Firewall Service<br />

Table 32 lists the <strong>FortiGate</strong> predefined firewall services. Add these services to any<br />

policy.<br />

Table 32: <strong>FortiGate</strong> predefined services<br />

Service name Description Protocol Port<br />

AH<br />

Authentication Header. AH provides<br />

source host authentication and data<br />

integrity, but not secrecy. This protocol is<br />

used for authentication by IPSec remote<br />

gateways set to aggressive mode.<br />

51<br />

ANY<br />

Match connections on any port. A<br />

connection using any of the predefined<br />

services is allowed through the firewall.<br />

AOL AOL instant messenger protocol. TCP 5190-5194<br />

BGP<br />

Border Gateway Protocol routing protocol. TCP 179<br />

BGP is an interior/exterior routing protocol.<br />

DCE-RPC DCE/RPC stands for Distributed<br />

TCP 135<br />

Computing Environment / Remote<br />

Procedure Calls.<br />

It is a means to call procedures from one<br />

application in another application, without<br />

having to know about what <strong>com</strong>puter the<br />

other application is running on.<br />

UDP 135<br />

DHCP<br />

DNS<br />

ESP<br />

Dynamic Host Configuration Protocol<br />

(DHCP) allocates network addresses and<br />

delivers configuration parameters from<br />

DHCP servers to hosts.<br />

Domain name service for translating<br />

domain names into IP addresses.<br />

Encapsulating Security Payload. This<br />

service is used by manual key and<br />

AutoIKE VPN tunnels for <strong>com</strong>municating<br />

encrypted data. AutoIKE key VPN tunnels<br />

use ESP after establishing the tunnel<br />

using IKE.<br />

all<br />

all<br />

UDP 53<br />

TCP 53<br />

UDP 53<br />

FINGER A network service providing information TCP 79<br />

about users.<br />

FTP FTP service for transferring files. TCP 21<br />

FTP_GET FTP service for uploading files. TCP 21<br />

FTP_PUT FTP service for downloading files TCP 21<br />

GOPHER<br />

GRE<br />

H323<br />

Gopher <strong>com</strong>munication service. Gopher<br />

organizes and displays Internet server<br />

contents as a hierarchically structured list<br />

of files.<br />

Generic Routing Encapsulation. A protocol<br />

allowing an arbitrary network protocol to<br />

be transmitted over any other arbitrary<br />

network protocol, by encapsulating the<br />

packets of the protocol within GRE<br />

packets.<br />

H.323 multimedia protocol. H.323 is a<br />

standard approved by the International<br />

Tele<strong>com</strong>munication Union (ITU) defining<br />

how audiovisual conferencing data is<br />

transmitted across networks. For more<br />

information see the <strong>FortiGate</strong> Support for<br />

H.323 Technical Note.<br />

50<br />

TCP 70<br />

47<br />

TCP 1720, 1503<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

294 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!