Hello,
Yes, with Checkpoint FW (R77) we cannot use site to site VPN with dynamic ip, at least with using certificate - which is not feasible with Meraki Z. We will investigate to purchase additional MX as suggested.
In resume, if I am not wrong
-Goal is deploy Z3 on remote site (home running xDSL and dynamic ip), so we can connect softphone or physical poe phone (as teleworker gateway)
-Purchase new MX on HQ and use MX as VPN concentrator
-Traffic arriving from MX will be inspected by our Checkpoint FW before accessing the LAN
Thank you all for your support
Have a great day