If everything has static public IP addresses, then you could configure manual port forwarding: https://documentation.meraki.com/MX/Site-to-site_VPN/Automatic_NAT_Traversal_for_Auto_VPN_Tunneling_between_Cisco_Meraki_Peers BUT, you are missing out on the benefit of automatic AutoVPN. Could you maybe point out that the MX is a firewall, and doesn't require another firewall to protect it? Otherwise how many layered firewalls do you need do you need to add to protect the existing firewalls? The discussion becomes circular quickly.
... View more