I'd be interested to understand your use case as, for MX-protected branches, Secure Connect is used primarily to provide secure Internet Access (hence the default route). If you provide your Spoke MX with any more specific route though, that will be preferred over the SC default route. So if you have a tunnel to a Hub in a traditional DC, which is advertising some routes for the services they host (typically from within RFC1918), that traffic would use the direct tunnel, not go via SC - but your Internet traffic would still flow via SC. You can also perform local breakout at the MX (full-tunnel exclusion), if you wish: https://documentation.meraki.com/MX/Site-to-site_VPN/VPN_Full-Tunnel_Exclusion_(Application_and_IP%2F%2FURL_Based_Local_Internet_Breakout)
... View more