I'm looking to add a second firewall to my existing setup, retaining the current firewall as a alternative route to the internet.
I have a HP Procurve 5406zl as my core switch
I have my network segmented with vlans like the example in the attachment.
My current firewall is on vlan100 and is the default route for all internet traffic
ip route 0.0.0.0 0.0.0.0 10.1.100.10
When I add my second firewall, is it possible to use a metric to force all traffic to use the new firewall as a default route, failing back onto the existing firewall if the route is unreachable?
And should I create a new vlan for the new firewall or is it ok in the same vlan as the existing firewall?