PhillipDAth,
I would definitely create a white list rule if there way a way to only "whitelist specific host /internal network". I definitely do not want to open it up externally in case an unpatched machine slips through the cracks & from what support said there was no way the segment the whitelist rule from Lan or Wan traffic.