The point is if you have malware on the machine and it's sending outbound traffic to a WAN IP and you have detected this because you have reviewed the syslogs and detected or determined that the traffic is dubious in nature, then you can block the outbound traffic to the WAN IP until such time that you find the malware using software tools on the machine to track it down. The malware cannot circumvent or come around the outbound rules that have been set on the router like it can on a host based FW solution such as a personal FW that runs with the O/S. The malware can at the computer boot process with a host based FW solution beat the FW to the TCP/IP connection before the host based FW can even be started to stop the connection. That includes any worthless Application Control in PFW's too. The router with it's outbound rules set to stop outbound if need be is not part of the computer and is not running with the O/S like the PFW or host based solution with the O/S with them being easily defeated.
That is the point.
Duane :)