Is it possible to have such ACLs setup, and request ports to be opened, instead?

Even with floodguard, I still seem to get hit for some reason, which SM/TP has always done a good job of helping mitigate manually quickly.

Just would like to keep support requests to a minimum,

Josh