Where I work there is a policy that the external Internet-facing firewalls be from a different vendor than the internal firewalls. That way if an exploit is found in the external firewall then hopefully the same exploit can't be used on the internal ones.
It is hard to tell whether this is actually worthwhile or an unnecessary expense.