EVPN: All roads lead to the firewall
Introduction In the past, I have worked with proprietary firewalls (Stormshield, Arkoon, Netasq). The experience was rather mixed: the whole thing is hard to debug, updates are gated behind licenses, prices are excessive, and there are many technical limitations. So many reasons to rule out proprietary gear for this kind of design, in favor of a Linux-based solution (FRR, BGP, nftables): open source, innovation, and independence. The idea: a hub-and-spoke design where the firewalls play the role of hub, and nobody talks to anyone without going through them. ...