1x HQ and 15x branch. Each branch has 2x SD-WAN Zones (one for wan1 a wan2 and second for IPsec1 and IPsec2 to the HQ). All traffic is sent through HQ. AD server, DHCP and DNS is running at the HQ and a DHCP relay is set up at each branch. Unfortunately, I do not know how to achieve that the DHCP relay can use both IPsec tunnels (e.g. when the primary line/tunnel fails).
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.