It rather depends on what protocols you want LMS to use to "manage" devices, configured at such places as RME -> Admin -> Config Mgmt -> Transport Settings:
Here's a comprehensive list, with most for internal communications on the LMS host:
https://supportforums.cisco.com/docs/DOC-4677
One doesn't need to open "514/tcp (RCP port)" if RME isn't configured to use it, for example.
In reality you probably can get away with only opening a subset of the ports in this post below, plus UDP port 162 (SNMP traps) for DFM:
https://supportforums.cisco.com/message/1329162#1329162