I have a couple of thoughts. It might be easier to build a non-Meraki VPN between the two devices. This is like building a VPN between a Meraki and a non-Meraki device. https://documentation.meraki.com/MX-Z/Site-to-site_VPN/Configuring_Site-to-site_VPN_between_MX_Appliances_in_Different_Organizations When using AutoVPN over a private circuit the private circuit must be connected to the Internet. If when the MX's go to build a VPN they find that they both share the same public IP address (because of NAT) they then assume they are on the same private network, and then will build the VPN between their private IP addresses. https://documentation.meraki.com/MX-Z/Site-to-site_VPN/Configuring_Site-to-site_VPN_over_MPLS
... View more