You can not have the same public IP address configured directly on both devices at the same time. You can replace the watchguard with the MX, or you can put the MX behind the watchguard, run it in VPN concentrator mode, and NAT udp/500 and udp/4500 through to the MX. This will only work if the watchguard is not using IPSec for anything. https://documentation.meraki.com/MX/Deployment_Guides/VPN_Concentrator_Deployment_Guide
... View more