lol.
if you allow lan traffic through those ports, it's same as if they didn't have the firewall on at all.
a) in lan environment, the attack comes from the neighbor machine. the one you opened the hole for
b) those ports and services are the ones todays viruses use to attack you

so, it's totally useless to use firewall in domain network. imho.