RESOLVED:
I forgot to remove the ports from TCP_IN
My working config is:
TCP_IN: <empty>
CC_ALLOW: US,CA
LF_IPSET: On
FASTSTART: Off
-- It would be helpful if you also included the same instructions from CC_ALLOW_PORTS_TCP: "All listed ports should be removed from TCP_IN/UDP_IN to block access from elsewhere."