I assume you have the network set up as I had, the 6509 acting as a L3 switch between the different VLANs and their subnets.
What you can do in this case is to remove all SVIs you want to firewall from the 6509 and add them to the FWSM instead. If you then give the same IP to the FWSM interfaces as you had on the 6509 SVIs, and leave all rules wide open, you should have the same functionality as you had with the 6509 doing the routing.