In most of the NSX design documents, you will find that they usually consider connecting the NSX ESG(Edge Services Gateway) to physical routers which are usually the border leaf if you are using a Spine-Leaf architecture or Core switches if you are using a 3-Tier architecture. Below are some examples.
[Reference: NSX Design Guide
][1]
In certain scenarios, the above might not be always the case. Especially, an existing 2⁄3-Tier Firewalls exist and you cannot change the architecture. ...