Hi All,
Think i have worked this out then.
In order for clients connected to the same site as a one armed vpn concentrator in hub mode (in our case, this is a vMX in azure) ,you need to stand up a non-meraki ipsec to umbrella manually.
The documentation suggests that in this config, its not possible for auto-vpn traffic to utilise the hubs non-meraki tunnel to umbrella, so if you need branches to get to umbrella, you still need to set up spoke on-ramp auto-vpn connector tunnels to umbrella in the normal way.
I have it working in this way at the moment but wondered if anyone can confirm that this is the way its 'supposed' to work ?
Cheers
Shaun