The Cisco integrated fw is based on ZoneLabs' technology (or so I'm told).
We're using Integrity with the Cisco client, a 3030 and additionally using SecureID. The combination has proven to be solid and very workable. Integrity has a lot of nice features, and can give you a great deal more than the integrated fw in terms of granularity and (IMHO) protection. Speaking from personal experience the support from ZoneLabs has been great (far better than I expected!).
One thing particularly nice if you have users who like to "tinker" is that there is no user configurable portion to Integrity. I use it with the concentrator set to check for and deny access if Integrity isn't running when the VPN connection is initiated.