Replacing physical firewall with virtual appliance

We have a small environment that's mostly virtualized. But, we still have several physical servers that can't be virtualized.

We have a physical firewall appliance between our network and the outside. We need to replace it, and I've noted that most vendors are offering a virtual appliance. These are definately geared towards protecting the devices inside the virtual setup, but I'm wondering if these virtual appliances could also (efficievely, efficiently) used to protect our physical devices as well.

Any high level input on this? Physical space is a moderate priority for us; we're running out of room in our co-lo racks and don't want to expand.



