Any firewall is only as good as its programmer - and that goes for both software firewalls as well as hardware firewalls. Any system can be cracked - it just requires persistence and dedication on the part of the cracker. The best solution would be, as mike mentioned, to have both firewalls running but the only way to have a risk-free system is to disconnect all outside connections.

In spite of all of this doom-and-gloom, I have a standard router with DHCP/NAT addressing without a hardware firewall, using Zonelabs only as a software firewall, and have had no problems (but very interesting to review the intrusion logs every now and then).

Masaki