Hi, Could the core the central site have a pair of MX’s (HA), functioning as a Firewall and terminating the 7-8 VPN tunnels from their remote sites. Without needing to adopt the Split MX responsibility of Firewall and Concentrator? Yes, it can. Though things to note are below, virtual MX - can act as VPN concentrator only, don't have firewall functionalities. MX appliance - If you feel the load on your firewall is going to be too much along with the VPN concentrator role, you can go for "Umbrella" Integration and let umbrella handle firewall functions.
... View more