Thanks you for your response. I'm having difficulty understanding how the solution would function. When a public subnet is added as an interface, local subnet it can be advertised to the spokes via VPN. However, upon reaching the hub, the destination would be recognised as a directly connected network, preventing the traffic from being routed through the internet or the default route. As previously suggested, achieving this might involve a second firewall and an advertised static route. I'm seeking configuration options that are limited to the existing MX appliance, without requiring modifications to other network services, such as DNS.
... View more