V manualu jsou popsany options
gid, group, match the user groups sending this traffic
pid, process, match the process IDs sending this traffic
sid, session, match the process session IDs sending this traffic
cmd, command, match the command name sending this traffic
ale zatim jsem se nedostal ke zkoumani, jeslti se tak da opravdu povolit nejaky port jen pro urcitou aplikaci