There's something you haven't mentioned. Are you running the Contivity Firewall (either Stateful or Interface Filters?). If not, then the Contivity will NOT pass traffic between interfaces - the only thing it will do is Tunneling. It will be vulnerable to DoS attacks and the like, but as for penetration, you're pretty safe.
ETWatson brings up a good point that you will not be safe from problems that originate at the other end of the tunnel (your users or the "Branch Offices"), but you can set things up more safely by using TunnelGuard. Definitely look into that if you think that there could be problems on the users end.
One of the best reasons FOR running it in parallel is that you will eliminate one of the most common problems with tunnels failing to come up - firewalls. You will also maintain a better bandwidth state - your firewall handles some traffic, your Contivity handles VPN traffic.