Given that Juniper has almost EOL'ed it's ipsec VPN software, Netscreen Remote, and it won't support Win7, I was considering using a SA 2500 for an SSL solution, however I would like to continue to use our SSG 140 on the same connection for site to site vpn and other edge security. Is this a practical solution? If so, how should it be setup? Can the devices be cascaded, or is it best to connect each directly to the outside router and provide two routes into our network, one on the SA 2500 for SSL and one on the SSG 140 for ipsec vpn? If two routes, I would assume the ipsec would be the default route?
Why not just put the SA box behind the SSG and use an external IP and NAT to get to it through the SSG?