I'm looking to colo a 4 node server and one of the guys suggested to get a firewall. Well looking at the subscription fee's I kind of laughed as they are almost the same price as the hardware. My question is should I get just the hardware without any subscriptions or what?
If you are only going with to use 4 servers, and have no plans to grow, get a Cisco ASA 5505 or a Juniper SSG 5. Those should provide good service as long as they aren't doing a TON of traffic. Throughput is a little under 100 Mbps. I use them for small deployments like you mentioned above.
I don't have any subscriptions to deep inpection, or AV modules. On the Cisco gear it's a card that goes in the device (and a subsription too IIRC). On the Juniper it's just a subscription.