so, we are only using 1 internet connection. I added the subnets to the tunnel one at a time. We are now seeing that it has stopped renegotiating constantly and the mismatched SPI errors have gone away. When we run pings between my site and one other site, no errors. if we add traffic to a 3rd site at the same time, we see some packet loss When a 4th site is added, its nearly 100% packet loss. Its looking to me like the MX100 just doesn't have enough resources to handle processing this many routes across a tunnel. very disappointing. This would be only 1 of many ways in which the Meraki MX has proven to not be ready for primetime in anything more than the smallest of environments.
... View more