this document will help you
first create group for those where you want to allow ,move clients to that group, then create this policy, once policy is created, right click apply to the group you created.
Network traffic blocked due to the Endpoint Protection firewall
https://support.symantec.com/en_US/article.TECH203497.html
as per vnc make changes in step 9 and 10..