Quote Originally Posted by keezel
To clarify, it sounds more like you are looking for a backup portal (as opposed to layered security). Is this correct?
There will be web servers behind the firewalls, but they have their own redundancy. The important part is not losing protection and having service continuity if one firewall fails.

Quote Originally Posted by CybertecOne
Are you describing two boundary firewalls protecting the same WAN connection? Or do you have multiple WANs?

If you are looking for 2 parallel firewalls protecting a single WAN? By what method are you controlling the inbound traffic flow in order to take a specific route though a particular firewall?
The initial idea was to have one WAN connection, but the problem is, as you say, routing the traffic without creating another single point of failure.

As I read more it is suggested that two WANs with two ISPs is the best prospect for safety, but I'm also wondering if I'm worrying too much - some of the hardware firewall brands are quoting a 40-year MTBF for their units, although how they know that is beyond me ;-)