| description "<description>" | Specifies a description of the rule. Enclose the description in quotation marks.  | 
| dest | Specifies the IP address and mask for the traffic destination.  •	<subnet>—IPv4 or IPv6 address and mask:  –	For IPv4 addresses, use this format: xxx.xxx.xxx.xxx/xx –	For IPv6 addresses, use this format: x:x:x::x/xxx •	all-ip—Specifies all IPv4 and IPv6 addresses. •	all-ipv4—Specifies all IPv4 addresses. •	all-ipv6—Specifies all IPv6 addresses.  | 
| dest-port | Specifies a destination port or port label for this rule.  •	<port>—a single port number or a comma-separated list of ports with or without ranges (for example, 1, 2, 4 ‑10,12). •	A user-defined port label.  –	Interactive—Ports that belong to the system label for interactive ports. –	RBT-Proto—Ports that belong to the label for system processes. –	Secure—Ports that belong to the system label for secure ports. | 
| rulenum <rule-number> | Specifies the rule number. | 
| src | Specifies the IP address and mask for the traffic source.  •	<subnet>—IPv4 or IPv6 address and mask:  –	For IPv4 addresses, use this format: xxx.xxx.xxx.xxx/xx –	For IPv6 addresses, use this format: x:x:x::x/xxx •	all-ip—Specifies all IPv4 and IPv6 addresses. •	all-ipv4—Specifies all IPv4 addresses. •	all-ipv6—Specifies all IPv6 addresses.  | 
| vlan <vlan-id> | Specifies the VLAN ID.  •	-1 for all VLANs. •	0 (zero) for untagged VLANs. •	VLAN numbers from 1 to 4094 for tagged VLANs. |