Interesting project, familiar remit (limited changes to surrounding devices). Maybe you should call my employer, Telent Network Services.
An EVPN "collapsed core" can work just like the VC, doing both routing and switching, advantages being you now have
genuinely separate control planes, making future upgrades and maintenance a dream. It's a really good way to go.
Also, using IRBs is a good way to go, allowing maximum flexibility.
As I always say, it's not the starting state that is difficult or the end state; it's the migration that is complex.
where firewalls and dynamic routing protocols are involved, requires careful thought.
There is a lot of scope for traffic to head in directions you did not intend and to be blocked by the firewall.
Is a big bang move from the SRX1 <> MX links possible? What outage are you permitted?
I might do something like this......
Build the EVPN core.
Provision all the same VLANS ( VNIs in EVPN )
SPAN all the layer 2 between the MX10K <> MX304 in a temporary link back-to-back link
VRF Lite for any layer 3 over the same link ( typically firewalls in these scenarios are providing routing between VRFs ), just a guess here. As I do not know your traffic flows.
Links to the SRX will be tricky
Now you need to make a big decision: a big bang move on the SRX side ?
Or will you migrate services, VLANs, 1 by 1? The latter is more complex, but might be safer.
I might provision a new AE between the SRX <> EVPN core. But that needs careful consideration of metrics / stub areas to prevent traffic from trying to route via the SRX. Policy would need a simple update; the new ae1 (let's call it ae11 ) would be added to all the same places.
Or a big bang might allow you no changes on the SRX side.
I so wish engineers would set up /29s or /28s on a irb on the firewall links; it would make life so much easier for future engineers. allowing some more flexibility in migrations. There would be a 3rd strategy possible by spanning the ae1.100 between the MX10 and MX304s.
You could even think about converting your routed interfaces /30 to /28 irbs , which would tear down OSPF if I recall my theory correctly but cold be done with a few seconds outage.
That's enough free consultancy. Obviously, this is quite non-specific without the detail available; This should paint a basic picture. :-)
~
------------------------------
JNCIE-ENT 907
------------------------------