I have a DMZ that has a Cisco Nexus switch with VRFs as well as a physical firewall. Is it common in a DMZ environment to put the gateways for the DMZ systems on a Nexus VRF? Or should they be on the physical firewall? If they are on the VRF, then ...