For the most part, the ports in question would be listed here.
https://support.microsoft.com/en-us/kb/3185535
Although I would review it before using a trace to confirm what is there.
If you look at hthe Thread management in the default.pmd, there is a limit for 135,137 ports, you could block those, and or add in specific rules for the additional ports as needed, and then apply them to the roles for users, not the servers.
Does this assist?