SD-WAN(ish) design
Question regarding some Hub and Spoke SD-WAN configuration thoughts.
Hub - Single ISP, MPLS to remote spokes.
Spokes - 2 ISP + MPLS to main Hub.
Thought... Dynamic VPN from Spokes to Hub that utilize either ISP if the MPLS is down.
Question... is this possible?
Secondary question, is this possible if a secondary Hub is available that has access to the main Hub via MPLS/Direct connection?
So, with that out of the way I have the following scenario:
Hub1 - Single Internet Connection, Single MPLS connection.
Hub2 - Single Internet Connection, Single MPLS connection to Hub1.
Spokes - 1 or 2 ISP Connections, 1 or 0 MPLS to Hub1.
I want to set up spokes that can use a dynamic VPN to Hub1 if their MPLS connection fails, but the spoke has 2 internet connections. I would prefer to only have 1 VPN tunnel to configure, meaning that if WAN1 or WAN2 in the SD-WAN configuration is down, it won't matter as it would use the connection that is up to build the tunnel using a Dynamic tunnel configuration.
Is this type of configuration even possible? If so, how would you do it with FortiManager, which seems to think that every public or MPLS connection should use it's own tunnel. With the option of moving the external connections to dynamic IP Addresses to avoid static IP addressing costs, I'd just like to setup one tunnel that would utilize either WAN1 or WAN2, depending which one is up when the MPLS fails, with full BGP routing, OSPF routing, or whatever other option makes the most sense.
