it's a Firewall [...] it had a Live Update facility to automatically get updated rulesets and the such like
Isn't that a bit like a Band-Aid with a built-in razorblade? Would you then have to set up a second firewall to firewall these requests from the first firewall?
And an external, appliancey, firewall is solving a different problem: ZoneAlarm and friends deny unwanted outbound connections on an exe-by-exe basis and an external firewall wouldn't know enough to do that. Really you need both.
Peter