Let me clear something up: firewalls are mostly useless
What firewalls do: block certain ports you specify
What firewalls can't do: save you from ddos attacks, prevent getting hacked, save any traffic (it's read out at the main switch,not at your server so it doesn't matter if you block anything).
If there aren't any lower priveleged users on your server who could probably run processes on unwanted ports there is no reason to block any incoming/outgoing ports.You'd just block ports you don't use anyway and that just doesn't make any sense.
__________________
|