Thanks. I have set up the Third option Block all incoming connection in stealth wizard.
So CIS is doing its job, blocking all those incoming connections. Like I said, if the logs bother you, you can edit the global rule "Block and log IP in from IP Any to IP any where protocol is any" by unchecking the "log as a firewall event" box