I just want to verify that I can load balance two ISP connections in the following way (on an SSG 140): Each ISP is connected to an Ethernet port that is configured with the appropriate IP address data. I enable ECMP routing on the trust-vr. Now I add two routes. I configure the first with the IP address of ISP1's router as gateway and the second route analogously. I take care that both routers have an equal metric.
Then ScreenOS will automatically distribute traffic that flows from trust to untrust equally between both ISP connections on a per session base. I don't need to have control about what host in the trust zone is routed over what ISP connection.