If this were my project, I'd be inclined to have the both MX250s in HA and MS350 stack in one combined network. If the MS350 stack is using L3, you'd use unique identifier. If you keep it at L2 then use MAC address — Default. Separately, I'd put the other MX250s (pair) in their own separate networks as an example MX250-VPN-A (it's own network - same organization) MX250-VPN-B (it's own network - same organization) You would then use "Track clients by IP address" for client tracking, and its deployment mode is "passthrough" (VPN concentrator mode). This is the correct client tracking option for a standalone MX in VPN concentrator mode, as tracking by IP address is recommended when the MX is not the layer 3 gateway for clients. Client-Tracking Options
... View more