NAT firewalls are a necessary tool, but one should still have a software
firewall to monitor outgoing activity. Having a good hardware firewall
does not negate the need for a software firewall.
Except that a personal firewall application won't protect you while you're
installing the OS, wont protect you if the machine is compromised, won't
protect you if you run as an Administrator level account and encounter a
malicious bit of code that disables the firewall.....
I know many NAT router users that have been online for 5+ years without a
compromise, I don't know any personal firewall only users that can say the
same. While I'm sure there are clean systems with personal firewalls, and
I do believe in multiple layers, the idea of using a PFW for the typical
home user is really a joke their ignorant hands.
Also, consider that most corporations and many small businesses use
Firewalls (not those fake firewalls that only do NAT), and don't run PFW's
on their systems, it's fairly safe to run computers protected by a
"Firewall" at the border - keeping in mind that those cheap NAT boxes are
not firewalls (even though the vendors label them as firewalls). I've
been designing computer systems since the 70's and secure networks for a
long time, never had a system/user compromised in all that time, and not
one personal firewall application running on any of those systems, and
yes, they are mostly all Windows based systems/servers.
One last thing - if the user purchases a quality NAT box, they provide
traffic monitoring, and if WallWatcher supports the device you can easily
see what is going in/out of the network in real time.