Regarding the intrusion blocking. If the log already states it was blocked, then the IPS system is doing it's job correctly. It's not necessary to create additional firewall rules to block the port. Since you are connected directly to the internet, you will see these attack attempts more often. However, NIS FW and IPS is doing its job in protecting you from these attacks.
Thanks,
/Chester