Not sure if my subject line is correct, but here's what I have:
Four buildings with hub site-to-site VPN on MX84 - stable for long time
An underutilized Z3 that is spoke site-to-site VPN to "Building A" - stable for long time
I often connect my laptop from anywhere using Meraki's Client VPN to "Building A" w/ Cloud Authentication. - also stable for long time.
What I now need to do: Deploy Z3 elsewhere.
I have most things on the Z3 set up as desired.... I can get to data anywhere in the four buildings.
My issue is with outbound internet traffic. Traffic going to the internet is broadcast with the Z3's internet provider's IP. Conversely, when I am on my laptop Client VPN-ing, my outbound internet traffic is broadcast with Building A's external IP. I need the Z3 to act this way (broadcast A's IP) but am unsure on how to do this.
I was going to try things like VPN Concentrator but it seems some of these changes might have unintended consequences with my VLAN configs, etc. So out of caution, I ask here instead of experiment.