Good post, we had FWSM's in our old network. Since FWSM gives you statefull firewall features, to have VPN functionality it would be recommended to have a separate firewall (if you have the additional funds).
Good post here. Summary:* All OSPF enabled routers listen to/send LSA's on multicast address 224.0.0.5* DR/BDR listens on multicast-address 224.0.0.6 in addition to 224.0.0.5. This allows DR/BDR in a particular segment to figure out status updates. ...