Originally posted here by Nokia

So you now have one port secure!
Only another 65535 acl's to write and you can have all your ports filtered!
Not really. You can go the opposite direction and create access-lists to opening up the type of traffic you want and allow the implicit deny all to block everything else you don't want. This is much more secure than writing access-lists to block everything you don't want.