We have a real need to move our routing decision and security perimeter to the edge of our 2-HQ sites MAN.
Using firewalls at the security perimeter to support the full Internet Routing Table (IRT) and security policy presents issues - I agree, this is not gonna work well.
How about using Cisco 6500 series switches with the latest sup modules and max memory to support the full Internet routing table with dual firewall modules to support our security policy; basically 2 6500s each with 2 sup modules and dual firewall modules in each.
Comments welcomed
Thanks
Frank