Yes, a firewall on the same machine can be suborned - but how else can you do application-dependent firewalling? I want to let Opera use port 80 to the Internet, and stop IE - an external firewall won't do that.
Having said that, I do run PAT and a hardware firewall in front of ZA.
It's Old World (i.e. Europe), New World (the Americas), and Third World (neologism for the rest). No idea who coined the phrase, though.
Having said that, I do run PAT and a hardware firewall in front of ZA.