You want to provide internet access for the branches through your NOC, right? 1) Yes, you can do it that way. I would typically use a firewall DMZ. But in your setup, the internet traffic should flow through the content filter, which points to a VLAN on the Core. 2) The VPN-Concentrator only needs a default route. But your infrastructure needs routes for all branches to the VPN concentrator. 3) No Problem. Whichever model fits the branches needs. It is not the MX65 nowadays, but anything can be mixed from MX67, 68, 75, and up. For the redundancy: With Meraki, you only need the same model MX for HA but no additional license. This makes HA quite "cheap".
... View more