Hi Ajit, Thanks for the speedy response - kind of exactly what I thought, so thats good. Next quick question to throw in a little complication.... The branch site we are looking at putting in the Meraki to...they just have a single static public IP address. Their current setup uses a Zyxel USG310 box which we are looking to replace with the Meraki, on this Zyxel they have configured several NAT (well...PAT) rules to various internal servers on the LAN. If we replace this Zyxel with the Meraki and stand up the VPN as previously mentioned (backhauling all internet access), would we still be able to apply the PAT rules or would they be over-ridden by the 0.0.0.0/0 route? Thanks again Paul
... View more