On what type of platform do you want to do that. On a router, you can always create extended access-lists denying those ports and apply that access-list on the relevant ports.
E.g.:
access-list 101 deny tcp any any range 49000 49999
access-list 101 permit ip any any
interface fast-ethernet 0/1
ip access-group 101 in