Thanks @pb66 that was exactly what I needed to know. :+1:
On this occasion, google was not my friend.
All working now:

pi@emonpi(ro):~$ rpi-rw
Filesystem is unlocked - Write access
type ’ rpi-ro ’ to lock
pi@emonpi(rw):~$ sudo ufw allow 1234
Rule added
Rule added (v6)
pi@emonpi(rw):~$ rpi-ro
Filesystem is locked - Read Only access
type ’ rpi-rw ’ to unlock