Lets clarify. WAN1 = All other traffic WAN2 = Client VPN traffic For clients to connecting to WAN2 on the MX from the outside world, you would have use static IP (or meraki dynamic dns name) of the connection that you'd like clients to connect to the connection address. There is no way to make incoming INTERNET connections prefer a wan connection. For outbound traffic to client, make a traffic shaping rule that forces "any traffic" to "CLIENT VPN SUBNET" prefers WAN2. By doing this you have no fail-over for VPN clients, but you have achieved what you are trying to achieve. T-800
... View more