Thanks @alemabrahao @PhilipDAth for the replies.
I think I can get this working and would give it a try:
- I have the 2 sites that definitely will be spoke, so should be fine.
- I have multiple VLANs. I just need one VLAN to be disabled with AutoVPN, but then use non-Meraki IPsec peer to reach the same "disabled AutoVPN VLAN" on the other site. I have another VLAN that goes back to the AutoVPN that can reach to Hubs.
The reason for this complicated design is due to the another issue I posted on the other thread, which AutoVPN enabled VLAN breaks port forwarding. Even I am using split tunnel, I can never get port forwarding to work. And the port forwarding requirement is something I cannot ignore.