is this your office firewall?
That rule after rule 26 is an explicit Allow Any Any. You're pretty much wide open with that still in place. Would be worth adding in an explicit Deny Any Any rule in before it.
As you have access to the Outbound Firewall rules below your inbound I would also apply the vpn rules to your outbound rules also. Where you've configure Any for Source subnet can you not be more specific and tie this down just to your internal data subnet?
Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/
I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.