You cant go wrong with Cisco PIX, but an interesting alternative to look at is the Fortinet Fortigate. They have a a variety of firewall appliances for anyone from SOHO to ISP. What makes them cool, IMO, is that they also perform real-time virus scanning and IDS. Check out their enterprise line here http://www.fortinet.com/products/enterprise.html

-NeuTron