One example:
I want my Samsung TV to only talk to my DNS server, my Plex server (on a single port), and the internet (since it's going to do that to get to Samsung). No need for my TV to be able to ping, for example, my phone.
A Kindle: Just want that to go to the internet, no local services...