I have a simple two site WAN network with AT&T AVPN (MPLS Site to Site) w/NBFW off the default route, Internet setup WAN using Site A MX68 & Site B MX84 ... Single up-links per site to AT&T AVPN w/ network based Firewall...
With a Cisco RV160 Edge Router at each site as the WAN Up-link I can add a Site to Site VPN between Site A & B and still use the NBFW to the internet using the Cisco Routers ... But I wanted the MX devices per/site to be the network Edge & the Vlan gateways for the LAN.
If I replace the Cisco Edge RV160 with the Meraki MX units as the Network Edge w/vlan GW,
I use the single up-link WAN at each site & get through to the NBFW. All Good
As soon as I turn up the Meraki VPN Hub (Mesh), Each site loses the up-link to the NBFW...
Maybe I expected too much router similar capabilities of the MX devices to act like a Edge Router to the internet & VPN between the two sites concurrently...
I could always put the MX units behind the Cisco RV160 routers, but at that point I just wasted my money buying MX security devices for each site...
Does anyone know of a simple AB site setup using MX devices at the network edge to have S2S VPN plus Internet w/NBFW on a single WAN up-link path?