Hello Balakrishnan,
I went through the setup and below is my understanding:
The UTM device sits between the ASA and the upstream router which is the internet gateway for the ASA. Now, the IPSec traffic is encrypted and encapsulated traffic and hence no device can do any type of inspection on this traffic.
So the ideal place to put this UTM device is in the lan before the end hosts, where the plain traffic is seen and this would be scanned and later sent to the corresponding pc.
Hope this helps.
--
Ramya
--Please rate the solutions.