In essence, with a cluster, you do NOT want to run something that handles your routing.
In my opinion : for the love of god, and peace of mind, set your router/firewall by ways of hardware outside your cluster.
For a Non-clustered env its all fine, clustered, you dont want the firewall on it.
-...