The meraki doc on auto vpn with MPLS would work here. MPLS is more used as a generic term for any private WAN. Comcast ENS can function (as far as Meraki is concerned) in the exact same way as MPLS would. I'm quite curious on the reasoning on dumping Internet for ENS. That is the opposite direction most companies I deal with are going. ENS is usually more expensive than edi at the same speeds because it can require taxes that internet circuits do not. You also are forced to use comcast even if the area you are in isn't a native comcast territory. However if I was forced to use your setup, I would not be leaving the MXs in the site with no internet. I would do as you thought. Regardless you are going to have difficulty with failover, at least in an automatic way. I wouldn't really want to do it, but I can imagine a few hacky ways to leave the MXs via creating two vlans on your ENS, one terminating at Site A and one at B and then presenting those as ISP 1/2 to the MXs. There's a bit more work to it, but it would function and allow failover. Regardless, outside of crazy security or very specific bandwidth needs I'd see if you can reconsider using ENS. Comcast generally doesn't care how they get their money so you can likely change the products w/o incurring pricing changes.
... View more