Netuser,
a 2 tier install is fine for 400 users, i would setup the enforce box in the following config
Mirror OS drive
Mirror D drive or where oracle sits 450 gig 10 sas drives
since your are going to have the scanners in the enforce box i would suggest some higher hardware specs.
2 quad cores 16 gig of memory, this will allow for parallel scanning of file shares, servers, sharepoint
remeber oracle is only supprted under server 2008 and rhel 5 @ this point, so i you try setting it up on aix or something else support may have the option of not supporting you. also the rest of the scanners other then network monitor can run in vmware.