>Сабж! Например нужно оставит 80,21,53,и >1000
диапазон портов
${fwcmd} add 64000 deny tcp from any to any 25-80
или в твоем случае
${fwcmd} add 64001 pass tcp from any to any 80 out via ${if_ext}
${fwcmd} add 64002 pass tcp from any 80 to any in via ${if_ext}
${fwcmd} add 64003 pass tcp from any to any 21 out via ${if_ext}
${fwcmd} add 64004 pass tcp from any 21 to any in via ${if_ext}
${fwcmd} add 64005 pass tcp from any to any 53 out via ${if_ext}
${fwcmd} add 64006 pass tcp from any 53 to any in via ${if_ext}
${fwcmd} add 64007 pass tcp from any to any 1000-65000 out via ${if_ext}
${fwcmd} add 64008 pass tcp from any 1000-65000 to any in via ${if_ext}
${fwcmd} add 65000 deny all from any to any
${if_ext} - Внешний интерфейс