Hi everyone,
Have to merge 1 main and 2 remote sites that are on MPLS and Watchguard to Meraki + ISP internet.
But customer wants to keep the main Watchguard firewall at HQ and wants all Internet traffic from all sites go through it.
Here is what I started :
At first, only HQ (hub) and remote site 1 will be on Meraki, remote site 2 will still be on Watchguard and MPLS for sometime.
So, fulltunneling Internet traffic from remote site 1, and then telling MX84 at HQ to send all that Internet traffic into customer's Watchguard
MX84 : static route 0.0.0.0/0 on Lan cable pointing to Watchguard
+ other static routes to reach HQ's LAN and remote site 2 that is still on MPLS and Watchguard
Would there be any issue with MX84 at HQ being connected to its Internet 1 and 2, AND also having that 0.0.0.0/0 route pointing to customer's Watchguard.
I guess this way, even the MX84 Meraki cloud communications would go through the Watchguard ; so Internet 1 and 2 would only be used for AutoVPN ?
Maybe I don't see it the right way
Passthrough between Watchguard and LAN ?
Maybe VPN concentrator one-arm like in a DC (not even touching LAN at HQ) ?
thanks,