Hello Wolfgang,
<<Routing via the central CO-gateway does not need any dynamic routing protocol nor static-routes to the networks behinds your 14xx gateways. The routing is done via the routing capability of your vpn community.>>
We used RouteBasedVPN with Tunnel Interfaces and with this configuration we need OSPF.
After your last post I did change my concept (see attachment).
I think we should concept more then one Firewall as CO - Gateway and add all of the CO - Gateways as Center Firewall to the VPN Community.
That should match our requirements for the most use cases. Via OSPF the best route to the destination network should be automatically selected. If one CO Gateway is down routing should switch to one of the other CO Gateways.
Has anyone this tried before to add more than one CO Gateway as Center Firewall to the same community?
Regards
Florian