Thanks for the reply, Philip, much appreciated. The ambition is to have no inside server presence, so StrongSwan probably not an option, but I'm toying with the idea of relocating our Juniper SRXs when they're no longer required in our DCs, they would offer similar functionality. But VMX is my preferred approach, will have a read and see if I can get all the stakeholders on board, and hopefully get some endorsement from Meraki to scale up that far - thus far they've advised us to run multiple VMXs, but that sounds like a little too much engineering to me. thanks again Andy
... View more