We deployed another vendor's WLAN and have been using Aruba WIPS to defend it for some time.
We are now replacing the other vendor's gear with iAP...
We installed 5 access-points at each store and one WIPS in the middle to detect intruders.
We had to tell the controller not to classify our WLAN as rogue, thereafter the WIPS have done an excellent job of detecting and alerting. We didn't install a high enough density to be effective at containment, but they work for that when the rogue is close enough.
If I was going to do it over, I'd just go with Aruba. If that weren't an option, I'd have put out more WIPS to better protect the WLAN.