我给个范例:
先设置服务:定义dzh(大智慧)的端口
set service "dzh" protocol tcp src-port 0-65535 dst-port 22221-22224 timeout never
set service "dzh" + udp src-port 0-65535 dst-port 22221-22224
再设置策略:禁止内部访问外部用这个端口
set policy id 1 from "Trust" to "Untrust" "any" "Any" "dzh" deny log count
set policy id 2 from "Trust" to "Untrust" "192.168.10.0/16" "Any" "ANY" permit log count :lol