I just wanted to say thank you for replying back to me and getting me to keep looking at the problem. I did not really find an answer but, My script runs under the user profile in GPO and adds the VPN in split tunnel mode. then only modification I need to do is set the metric for ipv4 in the vpn to 1 and all the dns traverses the tunnel. and end user still has internet via the split. with all that said, Meraki Tells me my original configuration should work should not need split tunnel can use Gateway on remote device, but no one can tell me this configuration. so I am up and running but still want to explore the full tunnel via the vMX if that is even possible. thank you again.
... View more