Well, it depends on what you want to do. If you want to stay Cisco, you have 2 choices. If you need just firewall experience, get either a PIX501 or 506 with PIX OS 6.3 or newer. If you want to do some stuff with DMZ ports, things get more expensive. A PIX 515e or larger is needed to get dmz ports, plus an interface card is needed to plug into the chassis in order to get those ports. In my opinion, a 501 is fine for learning NAT, VPN, etc. If you can master the capabilities of the
501, a dmz setup won't take you long to learn when you finally get your hands on one.
-Brian