> No need to worry about patching/locking down anything else, like you'd
> have to consider with a linux  box. In a very over-general sense, too,
> dedicated tools seem to work better than multipurpose ones (ever tried
> to cut down a tree with a swiss-army knife saw-blade?)

There are also OSes that have a very sane set of defaults and can safely
be  run. e.e.  With  OpenBSD, the  only service  running  by default  is
OpenSSH and you can easily restrict  who has access to that service with
a firewall  rule. Also,  you see  just as  many problems  with dedicated
systems on bugtraq.

> so, does anyone have any experience with hardware firewalls?

I've run Checkpoint  (though it isn't a hardware firewall),  but I would
rather use pf.

