Um, no. You should absolutely be doing both. Defense in depth is the only way to remain secure in failure of any other component. A firewall WILL NOT PROTECT YOU FROM THAT.
For example, you just put on the firewall and leave a daemon running on localhost as root. The firewall allows connections from localhost by default (as most do). An attacker finds a hole in your webserver and is able to run scripts in the httpd context. The script makes a connection to the daemon on localhost, exploits it, and now has root privileges. With root the attacker modifies the firewall rules to allow access. You are now fully exploited.
Had your daemon been secured they would have only been a takeover of httpd and daemon accounts and not a full system compromise. Privilege separation is extremely important.