Absolutely, but to build a suitable independent logging system that understands the protocols used, and all the relevant fields, would be hugely complex.
Ultimately, you'd need to log every packet in full if you don't trust the core vendor - a control packet could contain an undocumented field like 'cmd', whose value is executed by root...
That's the kind of threat you'd be looking to catch. That means you'd need to terminate transport layer encryption on this "firewall/log" system, so that you can see and log the content of control messages.
Ultimately, you'd need the cooperation of the vendor to actually build a system that could meaningfully understand these control/management messages, and therein lies the problem!