CA Access gateway hosts a variety of functionality + feature in addition to just being a Proxy. I generally do this in POC and Lower Environments (E.g. Dev); where I need to demo functionality e.g. Proxy, Federation, AuthAzWebServices, SessionAssurance, STS etc (I run all the features on the same instance of CA Access Gateway).
However in Production I may just segregrate based on traffic pattern e.g Federation Traffic goes to SPS1 and SPS2, whereas proxy traffic is handled via SPS3 and SPS4. Hence designing strategically is quite important after accounting for following points i.e. the features, future purposes, capacity planning etc.
Regards
Hubert