lets say tcp outbound connection to x.y.z.w address at port 5555 is required
to open certain internal clients only ( lets say 10.1.1.5 - 10.1.1.10)
The rule should not apply to any IP addresses in the internet.
The rule should apply to only specific IP address.
Certain internal clients should only get this access...from inside...