Your Phase 1 and 2 crypto settings must be right, because the VPN is operating for some period of time. You could ptentially check the times match at both ends. It sounds like the VPN re-negotiation is failing. This should happen before the original VPN expires. It may be that the two ends handle this in a different way - and may not be resolvable (at least not without firmware upgrades). On the Meraki side, I would tend to use the 14.x firmware, such as 14.37. I also see that you are running the VPN with NAT between the two ends. You should avoid this kind of configuration. Are you able to get public IP addresses on the two VPN devices directly (the MX and the Juniper)?
... View more