Not sure if this answers your question: but all wan interfaces need reachability to the meraki cloud https://documentation.meraki.com/General_Administration/Other_Topics/Upstream_Firewall_Rules_for_Cloud_Connectivity You could still use other default routes for the vpn overlay, or local routed lan subnets
... View more