The default configuration is fine (I have it at that, excluding few ticks here and there to get the sygate home network working).
The best protection you can have is by knowing what you're allowing and what you're denying.
The best protection of course is, that you disallow all traffic and only generate advanced rules that allow specific traffic to specific ports of specific ips.
But that's a bit of a hassle
//edit:
Ok, ignore my stupid errors

There shouldn't be two 'the best protection' rows, don't know why I typed them there, but ignore the loss of idea there