A brief pointer to Andrea Dainese's blog post on off-path firewall design using traffic engineering, addressing why a VRF and associated router may be needed between virtual servers and a firewall. The discussion in comments expands on related approaches including policy-based routing (PBR), BGP communities for traffic steering, and integrating firewalls with VXLAN or MPLS in data center environments.
2 Impressions