Hence why we're keeping it simple. You either have port blocking enabled (default), or disabled (on request).
An option we considered was to block NETBIOS and SMB for everyone with no exceptions, but that seems a little cavalier - we wanted for customers to have the ability to opt out of this filtering as there may be legitimate use cases for some customers to use the ports above for non-standard use. You never know if a developer somewhere has written an application that uses these ports (for a different protocol!) and is hard coded .....

