Deny by default?

Can someone show me the default firewall example that they give in the manual taking a ‘deny by default’ stance?

They block tftp, netbios.. etc and allow all udp, why not deny all udp except what is allowed..

How do you do this for tcp, udp, icmp, gre.. IPs..

Thanks in advance.

You can find very different examples in the wiki firewall section.