Aye... Netscreen is a little less configurable where ICMP messages and non-standard services are concerned.
Both the netscreen and ASL seemed to handle the various DoS attacks well (by dropping packets)
I recall that the Netscreen doesnt do source natting when using aliased ip's properly, cant remeber off the top of my head _the exact scenario_ but I can email you parts of the report, if you email me at the weekend.
Depends what you want to do with them all, Out of prefference I would use asl, as a matter of cost, and principle. (not using the application proxies in asl) just as a packet filter/vpn gw.