Very likely that is the same concept as Meraki AutoVPN over MPLS. https://documentation.meraki.com/SASE_and_SD-WAN/MX/Design_and_Configure/Configuration_Guides/Site-to-site_VPN/Configuring_Site-to-site_VPN_over_MPLS As long as there is an exit node to the internet where the MXes can call home, and get information about their peers, the VPN should build between the MXes directly - eventhough each peer only has privately routed IP adresses. The MX'es require Internet access, otherwise they won't be able to get information about eachother and establish VPN connection. However, if Internet access is lost, the VPN connection will not go down immediately, as peer information is purged over time. Internet access to the registry matters only if there's a change in contact information after the VPN tunnel goes down. If contact information between the peers are the same, the VPN tunnel will go up again, even if Internet access is still missing. However, after a couple of hours, the peer information will be purged, and the tunnel will go down again. https://documentation.meraki.com/SASE_and_SD-WAN/MX/Design_and_Configure/Configuration_Guides/Site-to-site_VPN/Meraki_Auto_VPN_-_Configuration_and_Troubleshooting#VPN_Registry_Disconnected
... View more