The rules you are entering are bi-directional. In one screen, you qualify packets flowing from the origin to the destination and the reverse. This is why you are allowed to specify the interface twice.