An IP filtering Firewall can ensure that only those hosts which are intended to scan are actually scanned and that anything else NOT intended to be scanned is left alone (like sensitive servers).
Nessus is adversely affected by an IP filtering firewall, as it's then unable to access every port and every machine.