| description <description> | Specifies the description for this rule.  | 
| port1 <port> | Specifies the first port number.  | 
| port1 <port-label> | Specifies the first port label. Valid values correspond to port labels defined previously. | 
| port2 <port> | Specifies the second port. | 
| port2 <port-label> | Specifies the second port label. Valid values correspond to port labels defined previously. | 
| protocol  | Specifies the protocol name or protocol type. Valid values are: •	tcp •	udp •	any (This is the default.) | 
| rulenum <rule-number> | Specifies the rule number.  | 
| subnet1  | Specifies the first subnet. Valid values are: •	<network>—IP address and mask for the service rule. Use the following format: XXX.XXX.XXX.XXX/XX •	all—Specifies all IPv4 addresses. | 
| subnet2  | Specifies the second subnet. Valid values are: •	<network>—IP address and mask for the service rule. Use the following format: XXX.XXX.XXX.XXX/XX •	all—Specifies all IPv4 addresses. | 
| vlan <vlan> | Specifies the VLAN number. Valid values are: •	all for all VLANs. •	Zero (0) for untagged VLANs. •	VLAN numbers from 1 to 4094 for tagged VLANs. |