For a port scan pick the threshold you'd want before triggering the correlation rule, lets say a host has to hit 200 different ports on a single server for the correlation rule to fire. Setup the rule similar to below, mine is looking for external IPs only.
Then setup the "Advanced Options" so that the correltion rule is looking for a number of distinct events. In this case I have modified the "NumDests" to be 200.
How were you able to specify port not in 
I'm on 9.5.1 MR2 and it's not letting me specify anything outside of 1-65....
To solve this problem go to the event that is generated and get the signature ID, then you need to create a correlation rule that base on this signature ID and you can customize your needs based on your requirement.