This is a good general guideline for basic VyOS configuration, and covers zone based firewall (but it lacks IPv6 which can be done following similar steps)
Probably 99% of the forum will be better than me to answer this, but in your case, isn't it better to use the Cisco as a L2+ switch, the ICX as L3 and the FW in the transit VLAN ?
So you trunk all the VLANs from ICX to Cisco (with a LACP if too much traffic) and let the ICX handle the routing...
You will probably need to create the thread on the software side of the forum, and also put some kind of information like:
*NGINX config files
etc, so someone can pick it up and take a look at it.
Hey, I'm spending my holidays on CA (till Dec, and was wondering if someone is willing to sell an LGA2011 MB with or without CPU(s).
I'll buy up to 2 as I will give one to a friend back in Argentina.
Couldn't get the deal on the X9DRD, but other ones could be fine (standard form factor up to...