Yeah, in fact, the internal windows xp firewall only controls inbound connections, but that is not all, that should be controled. This topic is also a debatable one, because many users state, that a router should be protection enough. Personally i use both. I recommend you a security suite like G-Data oder Bitdefender. Norton is still not bad.