Hi James, Thanks for your reply. We are trying to achieve the following: 2 diversely located firewalls (split by L3 connections) which act as a termination points for SSL VPN, IPSEC VPN, Internet Traffic and several other services. The link into the main firewall is at risk of becoming oversubscribed and our idea was to share some of the load (i.e. IPSEC VPN) onto the other firewall with its own Internet link. Problem is that we would still require a failover scenario, so an Active/Active pair requires the additional link and the Active/Passive puts all load onto the Active firewall. It may be that our only option is to upgrade the Internet link to the main firewall, but we do run the risk of the device itself being degraded by the amount of processing it has to carry out. We basically thought that the firewall sitting doing minimal processing could be brought into play to even the load. Andrew
... View more