Hi @GIdenJoe, That is a good question and a good representation of your thoughts.
So, even though there are two tunnels establishes on both uplinks and even while doing active-active VPN, We can only control outbound traffic, the inbound traffic will always come to the primary WAN interface.
Let us consider your analogy and assume WAN 1 is the primary WAN interface on both the hub and the spoke (This is configuration under "security & SD-WAN > SD-WAN and traffic shaping") then the traffic will flow in a below-specified way.
No SD-WAN policies configured:
Traffic will flow from WAN1 of one site to WAN1 of the second site
SD-WAN policy configured to send traffic over WAN2:
Traffic will from WAN2 of one site to WAN1 of the second site
When WAN1 is down, traffic will flow to the WAN2 interface to the spoke site
I hope this answers your question, let me know if you have any questions.
Cheers!
Raj
If you found this post helpful, please give it kudos. If my answer solved your problem, click "accept as solution" so that others can benefit from it