Hello,
We want to integrate firewall with out ACI multisite setup to segment the traffic between different BD and to internet. We dont want to do this using contract and also not with Service node integration in ACI.(L4-L7 Firewall)
Want to know is there an option to do this using L3Out to firewall.
If we do L3 out all the traffic between ACI to internet filtered on FW but how can we filter the traffic between BD's.
If we move the BD(Gateway) to the firewall and keep ACI only for transit (no unicast routing for BD) will it work?
Any other way than enabling host routes to solve the problem of firewall dropping asymmetric traffic?

Thank you