I normally have a group of management IP addresses which I create a rule for to allow them to access the firewall using CPMI (and some other FW-1 ports), ssh, ftp and https.
mgmt_IPs > firewall > CP_mgmt > allow
Under that put a stealth rule in as well,
Any > firewall > any > drop.
Chris.
**********************
Chris Andrew, CCNA, CCSA
chris@iproute.co.uk
**********************