>We're thinking on vMX just because of the third VPN, because we think that we can do an third-party VPN from one MX105 to AWS, and two VPNs from another MX105 to vMX on AWS You can't do this. You can also only use a single non-Meraki VPN from the MX to AWS, and you can't failover between the WAN links on a single MX. The only way to achieve this is by using a VMX and AutoVPN. You can either use a transit VPN (like I linked to) and put a VMX there, or you put a VMX into each VPC. The VMX will build an AutoVPN tunnel to both WAN ports on an MX.
... View more