There can be a moment when you are creating firewall rules but you forgot to add service you dont remamber about. You could look for service configs but you could also check on which port those listening:
netstat --listen - or - netstat -l
If Local Address is * (for ipv4) or [::] (for ipv6) you know that those service bind to every interface, but those starting with localhost (ipv4) or ::1 (ipv6) those are local service.