Hi,
Cisco VPN concentrator is not a pure firewall- below is the extract from Cisco VPN conc Q&A with ref to the same:
Q. Does the Cisco VPN 3000 Concentrator Series have an integrated firewall? If so, what features are supported?
A. While the series has integrated stateless port / filtering capabilities and NAT, Cisco suggests you use a device like the Cisco Secure PIX Firewall for the corporate firewall
With reference to placement of the VPN concentrator, it can be placed in front of, behind, parallel to, or in the demilitarized zone (DMZ) of firewall based on your design requirement.
The DMZ implementation- gives you more control on what the remote users can access (good in terms of firm security). In parallel to ASA - basically opens your LAN for remote partners.
hth
MS