we have same (just a proxy)app running in two diff DC's and needs to be connected using a effective solution. customer have black fibers and we are reluctant to just use a layer 2 trunk or Layer 3 (what if we miss any layer 2 traffic).
We are looking to have single pair of N9K switches in each DC to connect segmented servers with firewalls and SLB as front end. The switch will provide L2 segmentation and L3 aggregation using VRF(acts like a composed access/dist/core) and Firewall will be used for inter segment routing.
Is it possible to use VXLAN-EVPN in the same switches that connects rest of the devices and extend only VLANs that may require extensions. or simple VPC will work with any additional measures to avoid l2 limitaions.
Supported DCI in NX9K-EX in small DCs
VXLAN-EVPN is a good solution for this senario , although Nexus 9k supports VPC but it is not recommended .