I would like to suggest to Cisco, as an improvement option for further firewall hardware and software releases, to add an option for a protection on Firewall High Availability Failover link protection. For now there is only one L3 point interface for a Failover link per device, and the only way to have a bare minimum protection is L2 LACP or such interface protection. But other vendors, like Palo Alto, offer the possibility to configure a secondary L3 link on different L2 inferfaces for HA protection, and this offers the flexibility to have a HA Faiover secondary link through completely different path on another existing link between sites.