if you value your work not being stolen by american 3 letter agencies then would avoid anything with an Intel CPU that is backdoored through Intel ME (management engine) and cia, nsa or whatever are the only entities on this earth with custom intel chips without the remote backdoor
would also avoid any cisco appliances as they are also backdoored and not to forget they built the great firewall of china so fuck cisco big time as well
for firewalls / routers would do through pfsense:
https://pfsense.orgis opensource operating system, u can do your whole network infra through it, on any desktop computers, can add 10GB/s RJ45 and 10GB/s SFP+ networking cards
then do the infrastructure of the network with redundancy and whatnot with load balancing, LAGG and whatnot, then add in the switches and whatnot
great 2 network designs with redundancy in mind: