Curious, for those of you who replied that they installed SP2, and are running Kerio, but disabled SP2's built-in firewall - are you running Kerio 2.x or 4.x? And are you aware of the issues with (at least in 2.x) boot-up and shut-down loss of protection with Kerio? The biggest advantage that I've seen, with SP2's built-in firewall, is that it is active throughout the bootup/shutdown process, and thus cannot be easily breached, unlike most 3rd-party ones. Based on that, and my testing with Kerio 4.0.15 on SP2 rc1, I'm wondering why you aren't running *both* firewalls at once? I didn't notice any problem conflicts between the built-in one and Kerio. (Not to mention the subnet anti-spoofing protection built into XP SP2's firewall, that Kerio 2.x lacks entirely.)