Without specific details regarding the environment and overall network topology there may be another way.
Just as a thought: Consider two separate boxes.
Not the requirement per se but using one box means that a problem with that box could take down everything.
Separate boxes means that at least one side or the other would still be working.
You may even be able to set up some sort of crossover between the boxes where one box could do all of the "work" (to some degree at least) until its' counterpart is restored or replaced.
Think about the trade-offs, advantages, disadvantages, costs, etc..
No harm in considering the option.