That is the hard way. Buy an additional MX67 (will support up to 50 branches with single Internet connections) and put that in headquarters in VPN concentrator mode. https://documentation.meraki.com/MX/Deployment_Guides/VPN_Concentrator_Deployment_Guide This would plug in behind the Sophos using a single cable and would be a hub. All your branch MXs would be a spoke. The branches will auto-build a VPN back to the VPN concentrator behind the Sophos. On the Sophos, as you cut each site across, simply add a static route pointing via the Meraki VPN concentrator for each branch.
... View more