>my concern is that they will loose the tunnel in case ISP1 fails because the standby MX ISP1 won't kick in until both ISP1/ISP2 at the active MX fail, correct If ISP1 completely fails, correct, you are dead. If MX1 fails however MX2 will take over the VIP address. There is no clean way of handling the failover for non-Meraki VPNs. Another option is to get them a little Z3 and have them pretend it is an MPLS router, and plug it like they would plug in an MPLS router in their environment. Then you can still use AutoVPN.
... View more