SD-WAN redundant routing question
I have a high level question if a scenario is possible.
I have 2 main head office sites, with a traditional MPLS link connecting the 2, lets call them site A and site B, each site also has a leased line for internet access. Each site has a 300D HA pair for corporate firewall.
I also have remote offices with a DSL internet connection and VPN connectivity to site A, using Fortigate 60E DSL.
Is it possible to configure resilient VPN connectivity / SD-WAN so that if the internet leased line to site A fails, the remote office can still access resources on site A, via VPN to site B and across MPLS?
Each site has unique internal address, lets say 10.1.x.x/16 for site A, 10.2.x.x/16 for site B and 10.3.x.x/16 for remote site, the routing on the MPLS forwards traffic for 10.3.x.x/16 to site A, as traffic is expected to route from this firewall / VPN endpoint, traffic from site B to remote site is required so I can't change MPLS routing.
It's all a bit blue sky thinking right now, wondering if anyone has done the same.
