I can´t really see the reason to use a rule based firewall if you aren´t very initiated in how to create these rules. If you aren´t the result might be a system that look safe but in fact is wide open.
Even though I´m an experienced, no Pro for sure, I think it`s safer to use a
Firewall using Application-Based Intrusion Detection Systems.
I´ll have visible control over when a connection is to take place and have the opportunity to see what program, the remote address etc. and then if all is OK accept the connection.
I can´t see the benefits in using manually created rules, general or application specific except for in some rare cases. But both Sygate and Zonealarm support user defined rules if needed. If there aren´t any compatibility problems then witch one to use is a matter of taste in general.
Finally I know there are lots of Kerio lovers among board members and all of you of course recommend Kerio in favor of eg. ZoneAlarm or Sygate. But IMO you can´t compare these apps that easy. They are all firewalls but there are essential differences between a Rule Based Intrusion Detection System and an Application-Based Intrusion Detection System. This fact is is very important for a non experienced user and lots of folks reading these posts are newbies on this matter and trust the opinion of others and go for the same solution. A good solution but only if you have at least basic knowledge in ports and protocols otherwise it´s hard to configure Kerio and similar apps.
And in the end a result might be a system wide open.
Many various apps that need internet access also make it harder to create working rules. I know because I have tried Kerio, Tiny etc. more than once. To see if I my settings was right I used on-line security scanning and I had to add, change and remove more than once to get a working firewall. I´m no Pro for sure but I think of my self as experienced in general...but still It caused me quite some work to get it all right.
Here is a very good site if you like to test how well your firewall works.
http://scan.sygate.com/
LaZorMan