If you can put an MX (or MX+spare) into the third party DC do that. You can tell them to treat them like an MPLS router, and just plug them into their firewall (or wherever else they plug in WAN routers). Failing that, you will want to get an extra device just to terminate this VPN. Then on your hub MX's add a static route pointing to that device and redistribute that route into AutoVPN. That will give all of your network connectivity instantly. I often use Cisco ASA's or ISR routers for terminating the non-Meraki VPNs. You can also use an additional MX - but it must not be part of AutoVPN (really important). This guide goes through it in greater detail. https://www.willette.works/merging-meraki-vpns/
... View more