Depending on how you're routing, perhaps you could make the 3560 see the best path as through the firewall router while it's up. I.e., someone could still set the 3560 as the gateway, but their traffic would still transit the firewall if the firewall was on-line.