Try this as the body...
<firewallRules>
<firewallRule>
<name>rest-rule</name>
<ruleType>user</ruleType>
<matchTranslated>true</matchTranslated>
<direction>in</direction>
<action>deny</action>
<enabled>false</enabled>
<loggingEnabled>true</loggingEnabled>
<description>rest-api-rule</description>
</firewallRule>
</firewallRules>