If you want to protect against the kind of attach he hypothesizes to have experienced, yes. Trying to catch root backdoor on your machine by running a firewall on that same machine won't be much help. He called it an "external firewall", so I imagine it was a separate machine that noticed the outgoing requests.
Yes, there are inherent problems with the built-in firewall. The bad guys know it is there so any exploit that they install will likely modify the firewall to cover their tracks. External firewalls can be trusted more than built-in software.
I would be surprised if the built-in firewall even blocks any outgoing connections by default. I'm not on my MBP at the moment so I can't check for sure.