I use a broadband router and usually leave windows firewall enabled. I used to use "blackice defender" because it had great logging and customization features, but it (and zonealarm) never once detected an intrusion attempt after I started using the router so I quit using add-on software firewalls.
If I was really concerned I'd run a honeypot on an otherwise unused machine here in order to catch problems within my own lan, but so far I haven't felt the need to do so. A properly locked down broadband router with NAT will block pretty much everything you do not explicitly allow yourself.
That said, nothing protects you from yourself and if you click "yes" when the porn video asks you to run something in order to get the superspecial codec, then you get what you deserve...