Generally speaking you want to mark traffic as close to the source as possible. So ideally you have the VoIP device mark it's own traffic, and then you "trust" those markings throughout your network. Failing that, you mark traffic on the ingress switch port the VoIP device is connected to (in your case, your non-Meraki switches). I'm not clear if you can mark LAN to LAN traffic on an MX using a Traffic Shaping rule. Perhaps someone else can chime in on that part? If you can you'll find it under Security appliance --> configure --> Traffic shaping and go right to the bottom of the page for traffic shaping rules. Might be easiest to use a layer 7 classification for voice, and then mark it to EF.
... View more