P O L I C Y C O N F I G U R A T I O N
Configuring Service Groups
9-20
Security Appliance User Guide
Version 3R2
9
Destination Port Low: 24000
Destination Port Low: 24000
CONFIGURING SERVICE TIMEOUTS
Set the threshold timeout (in minutes) for a predefined service or
custom service using the
set service
command with the
timeout
option:
set service {name_str} timeout {minutes}
Use the default service timeout (5 minutes) or specify a new threshold
E X A M P L E : C H A N G I N G A S E R V I C E T I M E O U T
Increase the timeout on the predefined service FTP from 5 minutes to 15
minutes:
set service ftp timeout 15
save
You can use the following options to define the additional properties of
the service:
• Code Values and Type for ICMP Services
• Timeout Value
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
C O N F I G U R I N G S E R V I C E G R O U P S
You can use service groups to select a set of service objects and put
them into group using a single name. After you add service objects to a
service group, you can apply the services to a security policy, thus
simplifying administration. A service group can consist of pre-defined
services or custom services.
Service groups have the following limitations:
• Service groups cannot have the same name as a pre-defined or
custom service.
• You cannot delete a service group until you first remove it from the
policy.
• A service group cannot have another service group as a member.
• The all-inclusive service term “ANY” cannot be added to groups.