GENEVE decap is the hard part
A GWLB appliance must terminate the GENEVE tunnel — decapsulate UDP/6081, preserve the inner packet's true source and destination, keep both directions of every flow pinned, and re-encapsulate replies. Most firewalls expect to be routed through on plain IP, not handed GENEVE-wrapped packets.