Just one other thought, reading this again.
MG is not involved in setting up secure tunnels between locations - if that's what you need. That would be an MX (or a vMX) to do that. For best functionality you'd have an MX (or a vMX) at the other end too, but it could in principle be IPSec device; either another vendor's device, a compliant cloud service (SSE / SASE) or an MX / vMX that resides in a different Dashboard Organization.