At this point, our ICS network architecture should look something along these lines:
This architecture design segments the ICS network into an Enterprise Zone, an Industrial Zone, and an Industrial Demilitarized Zone. Redundancy at the cores is implemented by a VSS pair of layer 3 switches (for example, a pair of Cisco 4500-X catalysts) and firewall redundancy is achieved with an active-standby pair of any flavor of firewalls.