Yeah, everyone is right here. If you can get away with it, dont place the two on the same host. What happins if your host goes down? your firewall and your IDS are gone, also
what happines of someone knows your running an IDS system and tries to overload your
IDS by sending specially crafted data thats designed to trigger your IDS, it could crash, not respond, or ever fill up your disks from all the logging.

Anyway I would not recommend placing and IDS ont he same box of the Firewall. If you dont
have the money or the hardware, then go with the Firewall and configure TCP Wrappers
or some sort of small time IDS.

good luck