I have a situation where I utilize CacheFlow devices to serve up web content for a high traffic web site. In considering new secure architecture - I have two options, creating two seperate DMZ segments - one for the redundant CacheFlows and another that contains the physical web servers. The other option is creating one multi-tiered DMZ segment that utilizes another PIX between the CacheFlow segment (Outside) to the segment (Inside) where the physical web servers reside. From a security perspective, what are some of the advantages/drawbacks of each design. Thanks for any help that you provide.