Hi @GIdenJoe, That is a good question and a good representation of your thoughts. So, even though there are two tunnels establishes on both uplinks and even while doing active-active VPN, We can only control outbound traffic, the inbound traffic will always come to the primary WAN interface. Let us consider your analogy and assume WAN 1 is the primary WAN interface on both the hub and the spoke (This is configuration under "security & SD-WAN > SD-WAN and traffic shaping") then the traffic will flow in a below-specified way. No SD-WAN policies configured: Traffic will flow from WAN1 of one site to WAN1 of the second site SD-WAN policy configured to send traffic over WAN2: Traffic will from WAN2 of one site to WAN1 of the second site When WAN1 is down, traffic will flow to the WAN2 interface to the spoke site I hope this answers your question, let me know if you have any questions. Cheers! Raj
... View more