I have currently 4 environments with 7 Nethservers. One has it as UTM, Mailserver and for Monitoring, Backup and Inventory (project ongoing). Another as UTM and currently building a Monitoring. The other two are just UTM.
I always separate the UTM from the rest. The division on the first one is because the Mailserver is in the DMZ, the other one in Intranet.
All machines are virtual on Hyper-V