Typically the tunelling is done over the Internet - but at the end of the day it is just IP packets. So as long as the APs can communicate with the MZ concentrator it should work ok. The mian gotcha will be to make the APs and the MX both present themselves to the Internet using the same public IP when they talk to the Meraki cloud so that the cloud knows they are both on the same private network. Check out this guide about using AutoVPN over MPLS. Except your remote devices are APs rather than MX's. Same rules apply. https://documentation.meraki.com/MX/Site-to-site_VPN/Configuring_Site-to-site_VPN_over_MPLS
