Hi
When you’re talking about about spine-leaf architecture, does this mean you have a VXLAN running or just using OSPF to redistribute BGP prefixes into OSPF to get these subnets on your FW?
If it’s the 2nd option, then yes you can use OSPF or you could have been able to use full BGP from down to top instead of redistributing a routing protocol into another.
If the 1st option, then OSPF is used for underlay and you will have BGP on top as overlay for your Customer (Data) VRF between leaves/spines to interconnect with firewall.
Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question