Hi,
The Cisco Press book Designing Cisco Network Service Architectures has an excellent chapter on this.
http://www.ciscopress.com/bookstore/product.asp?isbn=1587142880
Each method has various advantages and disadvantages depending on your business needs and budget.
VPN Parallel to Firewall Advantages:
- No need to change IP addressing
- Scalable solution
VPN Parallel to Firewall Disadvantage:
- Decrypted PSec traffic is not firewall inspected.
VPN deployed in a Firewall DMZ Advantages
- Firewall can inpsect descrypted VPN traffic.
- Scalable soultion
VPN deployed in a Firewall DMZ Disadvantage
- Complex to deploy.
Don't forget to rate posts that are helpful.