Currently have a mainly Watchguard estate for our bigger sites with OSPF deployed and works a treat.
We have deployed some USG’s to smaller sites where we cannot justify Watchguard costs plus also have hardware left over from another project. These sites just have an internet connection rather and use a site to site VPN back to our data centre, 2 VPN’s one for each data centre, previously sites just connected to our USG-XG-8 at one of the data centres.
Going forward we are doing a site to site back to each of the Watchguards back at the data centre and can route to these fine, the issue is normally we would use OSPF but not found a great way to do this with these and secondly if we add the routes onto each of the VPN which has a higher metric it doesn’t like it.
We have certain traffic that needs to come back to the data centre and out on a specific connection what is the best way to do this or to get OSPF working so if we loose one data centre things will continue to work.