S2S and Remote Access Question

I have a pretty hefty Palo Alto internet edge firewall pair, but am considering changing vendors for our remote access and site to site. I've been told that my internet edge could handle the additional traffic on the Palo Alto, but what should I be considering when trying to decide to keep them all separate, like they are today, or merging edge, s2s and RA together into a single HA pair? Also, I see a lot of comments regarding issues that come up with Global Protect, usually during updates. What is the general consensus of GP for RA? Are there significant issues with it? Looking for any relevant or general information. Thank you