I have several MX64-Non-Meraki (SonicWALL TZ205w and TZ300) VPNs. Generally, all of them work without issue. However, for no apparent reason, some of them will stop passing traffic. If I look at the SonicWALL, it says the tunnel is online, but it isn't. Once I renegotiate the tunnel, the VPN starts passing traffic again within seconds. The other weird thing is that it doesn't drop all the tunnels between the devices. I thought we were getting false positives, as I could ping the site from my workstation VLAN, but I then found that I couldn't do so from my server VLAN.
Any ideas on what is causing this?
See if the SonicWall has an option to enable dead peer detection and/or keepalives.
I had the same problem with Sophos UTM's and I had to disable NAT-T. Meraki support had to disable it on their end. It might be worth looking in to.
I've had success in the past with having support disable nat-t. It was between an ASA and an MX65, but I had a tunnel that just kept... dropping. Up and happy for a while, then boom splat unhappy remote site with no DNS.
After support disabled NAT-T, it has stayed up successfully for almost two months. I hope you get the same result!