Hello, Starting the planning phase of application centric datacenter with our ACI fabric. Below is a quick HLD. Arrows represent contracts. Contracts with the ADC icon will utilize L4-L7 services for load balancing. We don't want any route leaking between LAN and DMZ so we've decided to use an enterprise firewall to isolate LAN from DMZ. I have this setup in the lab right now and working perfectly fine. Just wondering if I'm way off of common/best ACI practice. Any recommendations on how to improve design? Any potential risk or caveats I may run into? Any insight would be greatly appreciated. 