You can use a proxy or network rules to secure internal ports. Alternatively, you may change the default product security as specified below.
ProductSecurity.xml
<DATADIR>/config
secureInternalConnections
true