For sure this is achievable. Going via the traditional way , we will have DMZ specific F/W and DC F/W for ingress and egress traffic ,assuming you have a similar connectivity model from the servers to those segments , NSX can certainly protect your workloads. How you implement the F/W and Routing is purely a design choice.
i talked to my NSX dealer yesterday and we talked about the DMZ anywhere solution and i think that is something looks very promising as well. Thank you for the reply!