@KV we run the setup you have proposed using Enterprise licensing. All we allowed was standard Meraki ports outbound from the VPN concentrator MX HA pair IP on our edge firewalls. We have currently a Z3, MX64 and MX65 all on different public networks, but being part of the corporate SDWAN, other MXs are on private MPLS WANs. Been working fine for a couple of months (public units) and rest running for over a year on the MX15 release train. The edge firewall vendor can make a difference, I've seen elsewhere on the forums that Palo Alto don't play nicely with ISP failover in this setup. Ours are fine and the Z3 etc. Survived 2/3 of our ISPs going down, leaving only the tertiary alive. Didn't even see an issue from their perspective.
... View more