A simple and pragmatic alternative to circuit upgrades is to use multiple Internet connections for different applications. Thus we might use:
Or if its available, the use of FTTC circuits would allow significant higher transmission speeds.
This functional separation means dedicated bandwidth is available for each application and ensures that traffic spikes in one application have zero impact on the others. Your Firewall must of course be able to support multiple untrusted (Internet facing) Ethernet interfaces, each of which would be connected to a DSL Router. The circuits can be sourced from different ISP’s and, if your Firewall has the capability, automatic link failover can be implemented, thus delivering a highly resilient system.
Directing inbound services over specific circuits is normally done through DNS or client software.
See the excellent Juniper & Palo Alto Firewalls available from our X.COMM security division