CTO,

Yes, that's the general idea; however you are correct, TG2's solution had a switch at the front which does create yet another SPF.

I have noticed that some of the h/w firewalls can be set to pass all traffic if a failure occurs. In this case, two firewalls in series (as you initally mentioned) would do the job. I don't know what sort of effect it would have on traffic, though, if everything was being filtered twice.