Thanks for the response mpryor, I've done a bit of reading about CBRC to become familiar with it and will keep an eye on the performance of the environment. I've managed to set this up successfully over the weekend in the following config:
1x security server in the DMZ
2x Connection paired connection servers. One with two factor, the other without. Internal DNS pointing to connection server with out two factor
1x stand alone connection server with out SSL or blast for legacy Thin Clients.
Only downfall is separate pools for the Thin Clients, but these users don't usually need to pass View sessions between various devices. No tags required.