Thanks Philip, on my side I'm planning to use warm spare MXs with Dual ISP at each,, but unfortunately I can't control the other side firewall brand.
The vIP is working for each ISP individually, correct ? I mean ISP1 will have vIP between the active MX and the standby one public IPs, same for ISP2,, so in case the other side firewall dosen't support DNS VPN, and i ask the client to point their firewall VPN to the vIP of ISP1, my concern is that they will loose the tunnel in case ISP1 fails because the standby MX ISP1 won't kick in until both ISP1/ISP2 at the active MX fail, correct? If so, that will leave the solution of creating two tunnels one to vIP of ISP1 and one to vIP of ISP2.