Hi,
We have an external vendor where they have whitelisted the public IP from one of our SDWAN sites.
We would like to direct all traffic flows from spoke sites via the Auto-VPN tunnels, to egress this spoke site.
I believe this can be best done via a static route at the desired site, advertised into the VPN.
I would then list the next hop as an IP configured on the MX.
My assumption here is I should not use any downstream/ external IP interface.
The expectation here is once traffic is routed to the desired site, no local routes will exist for the service, and then will egress via the public WAN interface (Default route is still via WAN).
Can anyone advise if the above is correct, or if there is any best practice around trying to consolidate specific traffic flow via certain sites?
Thanks,