This article describes the TCP/0:0 configuration in custom service.
Scope
FortiGate.
Solution
In the Firewall Policy, custom service can be configured by selecting the ‘+’ sign under Service and selecting ‘Create’.
The parameters listed below can be adjusted. The Destination Port is set to TCP/0:0/ It is also possible to enable the Specify Source Ports TCP/0:0 service.
Once a custom service has been created, it is possible to apply it to the Firewall Policy. This TCP/0:0 is the inverse of ANY ANY. Traffic will use the source and destination ports set to 0, thereby blocking ALL services (any > 0).