Hey guys thanks to all for your answers. I reached out to Meraki support. First of all, they will enable FQDN to be configured on the Non-Meraki VPN peers, then The recommend custom profile is: Phase 1 Encryption AES 256 Auth SHA-1 DH group 5 Lifetime default 28800 Phase 2 Encryption AES 256 Auth SHA-1 PFS group Off Lifetime default 28800 After I had the parameters configured, they asked for my confirmation, and I guess then is when they enable the IKEv2 parameters for the specific VPN. Also, another recommendation is to create a test VLAN to be the one available for the VPN as the traffic from this subnet will be sent to the Umbrella CDFW
... View more