Check out this deployment guide for one armed mode. https://documentation.meraki.com/MX/Deployment_Guides/VPN_Concentrator_Deployment_Guide The other option is to run it n NAT mode. Plug the WAN interface outside of your firewall so it is direct internet access and a public IP address, and then a LAN interface on the inside. This option is likely to be the most reliable.
... View more