Between mx and the remote z3s?
MX must initiate it then, correct.
So we are looking at a rule...
MX internal ip (port range UDP 32768-61000), to any internet ip (UDP port range 32768-61000), for the tunnel?
Dont need any well known ike, ipsec ports etc, correct?
and then just a rule for MX to register with the meraki cloud.