QUOTE(p2u @ 10.05.2007 01:16)
I second that opinion: Looknstop and Jetico are very good products but require more knowledge, that's why I didn't mention them.
So now we have the following options:
KIS
Outpost
Comodo
Kerio
LooknStop
Jetico
I myself am running the inbuilt Windows Firewall (I don't believe in Outbound protection), but you can do that only if you have configured your OS for maximum security. Against Inbound attacks it's enough though.
I have used Jetico PFW 1 with KAV 6 MP0.
http://www.jetico.com/jpfirewall.htmIt seemed to work well, but as others have noted, it is not for the faint of heart. And one of the knocks (not for me) is that the rules are not importable. I have not tried Jetico PFW 2 yet. Perhaps I will before I upgrade to KIS/KAV 7.
http://www.jetico.com/jpf2.htmI have used the Sunbelt-Kerio PFW 4.3 (I still have a license for it) with KAV 6 MP0, and I liked it as well as any that I have used.
Note that some of the poor ratings for several of the PFWs have to do with leak-testing, and none of that means anything to me. Like Paul, I only use a PFW for inbound protection. Except when I am evaluating PFWs for nag factors.
ISTM that the most important factors in choosing a PFW are 1) absolutely, positively
no flaws WRT inbound protection, 2) absolutely, positively
no vulnerabilities introduced by merely installing the PFW, and 3) the PFW has the ability to protect itself against shut-down, modification and tunnelling. If a PFW fails on any of these, then IMHO, the Windows FW is a better choice.
Ron