Bear in mind that the non-Meraki VPN tunnels (i.e. Meraki at one end only), created this way are straightforward secure, point-to-point connections; you don't get the same resilience and traffic engineering capabilities (SD-WAN, basically) that you get through deploying VMX in AWS and using AutoVPN (MX at both ends).