| --index INT | Yes | — | 0-based position at which to insert the rule. |
| --iface TEXT | Yes | — | NIC friendly name. The interface must already be
enabled. |
| --action TEXT | Yes | — | pass or redirect. |
| --proto TEXT | No | any | Protocol filter. |
| --remoteip TEXT | No | any | Remote IPv4 CIDR filter. |
| --remoteport TEXT | No | any | Remote port filter (TCP/UDP only). |
| --localip TEXT | No | any | Local IPv4 CIDR filter. |
| --localport TEXT | No | any | Local port filter (TCP/UDP only). |
| --commit | No | — | Restart the service after inserting the rule. |