icp is not open by default, and admin is up only if you want it to.
if you are using carp, 3128 3130 are also opened (default conf).
and socks opens 1080 (only if you start sockd)
You dont have to use ACLS to deny specific ports, you can use the object tags in the obj.conf to do the same.
In this reply,
http://swforum.sun.com/jive/thread.jspa?threadID=97152&tstart=0
checkout the reply '3'. That explains how to add a regex to block urls.
but why do you want to deny port 89? (if your requirement is that you want to block a 'local' port -- as opposed to a remote port, -- what you need might be a firewall rather than a proxy.)