Over All I think it is a good first step to protect your networks but noticed in your suggested ports to block you are blocking VOIP ports. Beaware 5060-5061, 10000, and 16384 are voip ports.
-Michael