Hi Philip, Thanks for that info , its cleared up that point. I have been trying to understand why i couldn't get that flying for a while now. Yeah, i had thought initially if i could get the MX Hub to talk to umbrella SIG then that should do it and I have umbrella connectors on my spoke sites which work fine, but i cant seem to get the SASE tunnels up between the HUB and umbrella, should that work ? Not wanting to derail this topic but I was also looking at scenarios where hosts within azure need to get to the internet but via the HUB MX so policy can be applied, not directly out via Azure. Im fairly new to Azure so i may be missing something fundamental here but i cant get that to work either, im wondering if I need to be looking at something like a def route in azure pointing to the MX.... ? im not even sure if it can be done. ? Thanks again for the pointers everyone. Very much appreciated. Shaun
... View more