even you open 80/21 port, but the firewall tracks every connection session, with randomized syn number, try to hijack this kind of connection is impossible.
high-end firewall normally include IDS service, they can dectect nearly all kind of attack by using attack signature and with appropriated answer(drop, reset, alarm).
web server normally is placed in DMZ, so even attacker damages the web server, with internal network secured, you can restore the web server within hours.
in an enterprise evironment, without using a firewall is unthinkable,
high-end firewall normally include IDS service, they can dectect nearly all kind of attack by using attack signature and with appropriated answer(drop, reset, alarm).
web server normally is placed in DMZ, so even attacker damages the web server, with internal network secured, you can restore the web server within hours.
in an enterprise evironment, without using a firewall is unthinkable,