catch,

Why not run personal firewalls on top of locking down each of the machines like you described and running a high quality firewall?

If the system you described equals X, wouldn't doing this be like X+1?

- X