If you are halfway competent, you do not use inband IPMI at all. IPMI belongs on a separate ethernet jack or at least a separate VLAN, connected only to a separate secured admin network. Which sysadmins can connect to, but which doesn't have connectivity to other parts of your network or the internet.
But I agree that you should filter all the relevant ports in all networks, just in case somebody screws up.
But I agree that you should filter all the relevant ports in all networks, just in case somebody screws up.