You are going about this the completely wrong way. NAT the traffic on
your spokes going to the hub. That way you can have all spoke tunnels up
at the same time.Although I guess you could create an SD-WAN zone for
your IPsec interfaces and define that...