"Ottmar Freudenberger" <> wrote in message
news:...
> "Michael Jennings" <> schrieb:
>
>> It makes me feel better when it blocks outgoing Windows stuff I don't
>> feel like allowing.
>
> *Feelings* are anything but secure(ing the system).
What your link
http://samspade.org/d/firewalls.html recommends
is a cheap single purpose dual homed host running BSD and ipf.
Darren Reed's Internet Protocol Filter (ipf) is a firewall:
http://www.lindloff.com/deipf-howto.txt
Is this also your recommendation to home computer users?
A clean reinstall of Windows flushes out accumulated crap.
I tend to recommend that, and the NAT router samspade suggests
for those disinclined to get involved with ipf, his first recommendation
http://coombs.anu.edu.au/~avalon/ip-filter.html
which is a professional approach requiring time and attention.
As to the software firewall, despite the NAT router, there are packets
that the Sygate firewall blocks or questions - like those leak tests at
http://www.pcflank.com/art21.htm
The Windows XP firewall can't pass any of those tests. Perhaps the
Vista firewall could if tediously adjusted off default pass all outbound.
Default is fine if practices are perfect and Microsoft is trustworthy.
Since I am not perfect, and regard the world as being somewhat
imperfect, I don't think default pass all outbound is fine.