Perhaps this can help you a bit. https://documentation.meraki.com/Architectures_and_Best_Practices/Cisco_Meraki_Best_Practice_Design/Best_Practice_Design_-_MX_Security_and_SD-WAN/Meraki_SD-WAN#Decision_Point_3:_Are_PbR_rules_defined.3F If you configure your VPN tunnel in Meraki your MX will route traffic to to the other MX via autovpn. Subnets that are configured to participate in the VPN network will traverse over the tunnel. All others won't. If you still have some traffic within that VLAN that is destined to go to internet you can configure a split tunnel. Send only site-to-site traffic, meaning that if a subnet is at a remote site, the traffic destined for that subnet is sent over the VPN. However, if traffic is destined for a network that is not in the VPN mesh (for example, traffic going to a public web service such as www.google.com), the traffic is not sent over the VPN. Instead this traffic is routed using another available route, most commonly being sent directly to the Internet from the local MX device. source: https://documentation.meraki.com/MX/Site-to-site_VPN/Site-to-site_VPN_Settings#Tunneling Cheers, Ben
... View more