The WAN ports can be tagged, but can only belong to a single VLAN. You configure this via the local status page. https://documentation.meraki.com/zGeneral_Administration/Tools_and_Troubleshooting/Using_the_Cisco_Meraki_Device_Local_Status_Page#MX-Z_Series_with_Multiple_Dedicated_WAN_Links The MX will use its WAN IP to talk to the Meraki cloud, and does not need a seperate management network. If you have other devices needing to talk to the Internet that are attached to VLAN11, then you can connect those via the LAN ports and configure a VLAN11 there. Note this would be using private IP address space. https://documentation.meraki.com/MX-Z/Networks_and_Routing/Configuring_VLANs_on_the_MX_Security_Appliance
... View more