On a machine that can do 10Gb firware rate, it is well advisable to have your IDS/IPS to be a separate box. IDS/IPS "cost" alot of CPU power. It gets more expensive when you are talking about pushing beyond 1Gb. This is why you'll find several forums stating that if you have a firewall with 10Gb speed, separate IDS/IPS is the way to go. Otherwise, a firewall with IDS/IPS will not necessarily push 10Gb all together.