For instance, with "orange" internet provider, i know how to redirect the port :1234 from internet to :80 intranet... but only once.
This is cool for 1 non editable port.
Sadly I don't think we can close the :80 port. It is (was) used by all the chat software.
For the rest: never keep the box-user, never keep the box-software, try to never keep the box-ports. The bad guys KNOW this things. For a old but still used automation-device (witch can control big companies) it still the box-parameters. So... easy to enter into the programs.
It was the same for Americans money distributor !!! (now, the have a random password when send to the client)