Running into a scenario where we have an L3 9500 core with SVIs (Gateway) for user subnets for a given site. MX firewalls are going to replace a different vender firewall for outbound internet access and AutoVPN will be used to connect the sites together.
I suspect if a subnet's default gateway lives on the 9500 core (l3 core) then it cannot participate in AutoVPN if MX is intended to be at the Internet Edge in routed mode. Can you confirm my logic is true/false? Will the SVIs need to be migrated to the MX?