hi @lpopejoy - this feature has been requested for a long time. At the moment the Meraki documentation states: Considerations for VPN Firewall Rules When configuring VPN Firewall rules, it is important to remember that traffic should be stopped as close to the originating client device as possible. This cuts down on traffic over the VPN tunnel and will result in the best network performance. Because of this, site-to-site firewall rules are applied only to outgoing traffic. As such, the MX cannot block VPN traffic initiated by non-Meraki peers. It just isn't available at the moment. For this purpose alone we utilise ASA's for non Meraki s2s VPN's.
... View more