I run iptables on my nat box (Yes, I know it isn't quite as good as pf, but it does the trick for me.)
My windows box is behind that, and I've got the nvidia hardware firewall running (the one that comes with the nforce 4 chipset)
Then I have the generic MS Windows XP firewall running as well.
My other Linux boxes (the lappie i have running on Slax, and the MythTV box) don't have any extra firewalling on, but they are inside of my home network behind the NAT box, and they have very limmited usage outside of my lan (MythTV gets some RSS feeds, has NTP running, and downloads TV listings, the lappie I sometimes surf on, but mostly I just use ssh and IRC on it.)
I haven't had any successful break ins on any of my boxes.