Hello,
Have firewall but it is way more complicated to NAT to the MX in armed mode. Plan is to use routed mode, directly connecting to the ISPs. Spokes will access resource over vpn, and accessing internet using DIA and using some SD-wan feature to meassure qos over vpns and load balance traffic.
So i guess i can choose routed mode with BGP settings on vpn tunnel between hub and spokes, and with hub and l3 switches, because ospf will not learn route from l3 switches, it will just advertise. Did i understand correctly?
Thank you,
Best regards