Thanks Patrick,
I followed the instructions in the FAQ (which is for port 4242), and I see via netstat that the Z is still listening on ports 4992 and 4244, which is expected.
What I didn't expect is that I could still telnet to those ports. I would have expected with /bin/false that I would have been disconnected right away, and I am not. Since I don't run a PC to test to see if the sync function is really been overridden by the inetd.conf, I have turned back on iptables.
Call me paranoid, but I really don't want anyone even trying to sync to my Z.
Craig...