executed in.
It only filters incoming packets, and only then if there is nothing inside the system speaking to the source of the incoming packet. I don't need to mention the words Trojan, and backdoor now, do I.
So, anything is better then that. And I've heard good things of Kapersky, so I would definately go for it.
(oh, and as to the hardware firewall nix box too, go for it. Every layer is good, and allows for redundancy in the event of compromise or failure. Look at www.Smoothwall.org for a specially built free hardened 'nix firewall. They make a paid for version too, if you need more features.) |