Which architecture will most cost-effectively meet the requirements of deploying third-party firewall appliances for traffic inspection and NAT capabilities in a VPC with private and public subnets, while placing the appliances behind a load balancer?