Firewall: How to enable port 5038?

Need to access manager from another box and the iptables rules in FreePBX are different from what I’m used to.

What do you put in /etc/firewall/firewall-4.rules exactly to enable port 5038 tcp?

I guessed -A INPUT -p tcp --destination-port 5038 -j ACCEPT but that does not cut it…

Can be done in the GUI, Firewall, Services, Custom Services tab:

