In my case, I have two 7204 VXRs as the gateways with HSRP (I would use GLBP, but the guest vlan is NATed, so would cause some issues with sessions)... they both connect into the access switch (actually a 3750G stack with 4 switches).
The subinterfaces on the gig-e interfaces from the 7204VXRs are ONLY the "outside" VLANs.
So if you imagine this heirarchically:
< OUTSIDE NETWORK >
|
< 7204 VXRs >
|
(802.1q EXTERNAL vlans ONLY)
|
< 3750 G >
|
(802.1q EXTERNAL vlans ONLY)
|
|
(802.1q INTERNAL vlans ONLY)
|
< 3750 G >
|
(end-hosts in their respective INTERNAL VLANs)
Basically the "internal" and "external" VLANs are the "same" vlan at layer 3, just that they are layer-2 separated by the firewalls, so the 7204 VXRs do the layer-3 routing.
Hope that make sense.
L