If you don't want to deploy CPE routers to do what I described above, there is a new feature in MBG. If you deploy a cluster of two MBGs, one accessable from mpls, but not the internet, and the other accessable from the internet (but not mpls), they are clustered on their datacenter lan side... There's a new feature in 9.0 (and available in 8.1 as an override) that's called "ping before redirect" that tells the MBG to ask the set to ping an address to see if it's reachable. You need this if the set can't reach it's mpls MBG, it fails over to the internet MBG, but the internet MBG is still connected, via the backend lan, to the mpls MBG and so will normally try to redirect the set back to the mpls MBG (where the set belongs).. This feature, when turned on, will keep the set hosted on the internet mbg util the set can successfully ping the mpls mbg. Only works for minet sets, not sip, but it works.