Your scenario discussed will work. There are two common scenarios when deploying with a WAN. You run a VPN over the existing WAN, and this is the guide used for that: https://documentation.meraki.com/MX-Z/Site-to-site_VPN/Configuring_Site-to-site_VPN_over_MPLS The other is where you simply route over the private network (and you can fail over to AutoVPN): https://documentation.meraki.com/MX-Z/Deployment_Guides/MPLS_Failover_to_Meraki_Auto_VPN My preferred approach is to use the first method, where a VPN runs over everything. I also configure the DC exactly the same as a branch. I typically plug a backup Internet circuit into the second WAN port on the DC unit so if branches also have a separate Internet circuit they can fail over.
... View more