Enter a new service name, select TCP or UDP, and list destination ports or inclusive ranges such as 443 8443-8445. Select Generate and copy the CLI block into the intended VDOM. Ports must be between 1 and 65535.
Example: branch-web with TCP ports 443 and 8443-8445 defines those destination ports. It does not create a firewall policy or allow traffic by itself.
Use a new object name. Reopening an existing service can retain protocol fields not mentioned in the snippet. This creates a service object, not an allow rule; use it in the appropriate firewall policy. Source-port restrictions are not added.