if I am understanding the question, we can actually simplify it to a single ISP. I mean basically you want each firewall to be able to leverage having two available ISPs, correct? in that case, your approach would be the same as asking how you would configure a single ISP to work with a firewall pair in HA. and I believe the response would be to have an intermediate switch (or two depending on your desire for switch HA), so that the ISP is plugged into one port and each PA is plugged into another port (for a total of 3), and then just scale that up for 2 ISPs (likely private VLANs on the switch for each set of 3 ports). if that makes sense. i've had a day, so my brain is fried anyway. that's my excuse. ETA: You will be warned and very well educated to try to avoid putting PA in active/active unless absolutely mandatory, such as in the case of resolving asymetric routing issues.
... View more