We were skeptical about this as well. What we do is full tunnel the connection to our MX600 which has the advanced security features. At that point, the users at the Z1 site follow the rules from the MX600.
Found this helpful? Give me some Kudos! (click on the little up-arrow below)