My setup is that of your traditional legacy WAN hub (data center) and spoke (branch sites). Currently, my only Internet access is at my data center. Even though they are on private WAN connections, the branch locations' connection to the WAN is via FortiGate (for traffic inspection purposes away from the data center).
I am in the process of adding Internet connectivity to each of these branch sites (will also add secondary Internet connectivity at the data center as well in the near future). I have a fair grasp of what needs to be done and following the hub/spoke guidelines in the SD-WAN Branch Deployment Guide documentation; however, what I am missing is process/procedures or caveats in migrating an existing used interface over to a new zone. So what I mean is, if I have my existing interface in a WAN zone and policies are applied to that zone, will I be able to easily move that interface to the new SD-WAN zone? I know I cannot do anything with the interface while it references something, so I know I have to deal with these things, but I am just trying to make sure I am thinking of everything and have "all my i's dotted and t's crossed" as it were. I know once I move my interface, I will have to change all of my policies to reflect to the new SD-WAN zone.
Hoping someone that has done this can chime in and give some additional thoughts or guidance in case I am missing something.