many appliances provide multiple interfaces that you can configure for monitoring. Are you interested in protection at the edge? Across multiple VLANs? Consider whether you are interested in control from outside in or both directions. Also remember a single appliance is also a single point of failure. Most have the ability to fail open so as to not close down your network. I employ both a separate appliance that monitors traffic on all my edge entry points as well as an integral module in my ASA.