Originally posted by Chacal
It isn't worth crap. Disable it and get a hardware firewall, coupled with a software firewall like ZoneAlarm or Norton Internet Security.
The problem with zonealarm is when you allow connections, it's not port specific and you don't have much control over it.....all or none. If you do use ZA, when it asks to auto configure, choose NO and do it manually. Otherwise, you allow XP full access to M$ (call home, spyware, auto updates etc.) which can suck up bandwidth, not to mention send Bill info about your pc. I used ZA Pro, but still did not feel like I had complete control. ZA is not really a "true" firewall.
Tiny Personal Firewall is ok, but the free version is no longer supported and does a few security issues.. Kerio took it over and they do have a free version available. However, it's not for the novice as it can be confusing. Tiny does have a Pro version, but it has a steep learning curve.
I've used others, including Norton Internet Security (a takeoff of AtGuard which they bought out a few years back), but so far, the best overall firewall solution for me has been Outpost which I'm using now. Whatever you decide, anything's better than the XP firewall, just make sure you understand what you're seeing when something asks for access, especially server rights (YES, some M$ services will want that).
BTW, turn off all those XP services that aren't needed. XP antispy is a good start. Turn off QoS (Quality of Service Packet Scheduler) in your network connection properties for you NIC. It sets aside 20% of your bandwidth.