A duplication or redundancy factor is fine and doesn't hurt anything. If things are working as they should, your second line of defense will never need to be called upon.
Anyway and ultimately you will find that there will be very little (if any) suspect incoming traffic for your SW firewall to deal with when a properly functioning HW firewall is in place.
It is, however, a nice comforting, verifying reminder when the incoming traffic blockage count is almost non-existent (as it should be) with a properly functioning HW firewall.
Vince
_____________________________________________________________
[*** If everyone is thinking alike, then somebody isn't thinking. ***]