That depends. If you have exposed services, you could use some features of the firewall to geoip restrict incoming requests to prevent spam from China and Russia and whatnot.
If you don't have any services running on a publicly accessible port, then what would the firewall protect?