Hi there,
I installed some for work last year, the IT security bods put it this way:
Firewalls are like night club bouncers, if it looks alright i.e matches the rules, then it gets in.
IDS / IPS, are like advanced guards - they have the persons life history to check against.
so in this analogy, if for example a drug dealer was trying to get into the nightclub, the firewalls may let him is as he matches the dress code, while the IDS / IPS would do a full background check and kick him out.
Hope that clears it up?
Oh, and generally the IDS solution would site behind the firewalls on the inside, but that's not always the case.
Kev