The “simple way” is more complicated on our side because we have multi-VRF setup with one front VRF without access to internal network and several internal VRFs and tens of tunnels.
I don’t have a validated “classical” configuration and I’m little afraid of radical changes in a production environment...