Hi John,
I do not have an example, but can try to describe the general idea I would use: you could create an ACL that denies anything you do not need (you might want to allow ICMP) directed at the gateway IP (both v4 and v6 if applicable) and bind this to your outside interface. Traffic through the router is never sent to the router (if it is sent to the router, it is not passed on to other devices).
I would suggest you look into using the management port (VR-Mgmt) for management and restricting all management protocols to use that VR.
Thanks,
Erik