Being grafted onto the same NICs on the server computer that you might potentially expose to the Internet makes firewalling them a more difficult proposition. I get a lot of piece of mind from having management interfaces on an an out-of-band control network whenever possible.