It is a fairly simple setup, we need all sites (except 2 subnets) to pass VPN traffic between each other. The other 2 main offices have a wireless point-to-point link connecting them and they are not members of VPN tunnels between themselves, yet are members of VPN tunnels to all other offices.
Port 1 (physical interface) on our existing firewall of subnet 192.168.1.0/24 has a static IP assigned of 192.168.15.250
Static route is assigned that says destination is 192.168.15.0/24 use port 1 of gateway appliance 192.168.1.11
On the other side, subnet 192.168.15.0/24 we have a static route set that says destination 192.168.1.0/24 next hop is 192.168.15.250
This has been working for years using a combination of Fortigate 100D and/or Zyxel USG210 appliances along with our prior Cisco SA540 devices. Meraki support has not been able to assist in recreating this setup with their devices.