Default accept policy does not always make sense. Give an option to set the default policy.
However, default deny policy would be too strict for this kind of a packet filter. Without an option to allow a range of ports etc. it will be simply unusable.