So, I am interested in getting some remote teleworker units - Z3s to be exact - and connect them to an MX appliance (MX250) at our main office. The thing is, this MX appliance will not be our main exit point for the head office. We are using our existing network still, and have no plans to change this in future yet. This MX unit will therefor sit behind a firewall and handle all the Auto VPN requests only. It will then also be connected to our internal network, in order to serve the VPN clients with their internal site details. As a simple topology, this is what we have in mind: With the Meraki unit hanging internally, in order to provide internal VLANs for the users. I can connect this unit to our internet circuits directly, but I do not want to bypass the firewall at the main site, so choose not do do this. Is opening up the necessary ports for this unit all we really need to do to make this work? Has anyone actually done this before and gotten it to work? Would we only then need the Enterprise LIC, as technically that is the only function of the MX in this regard?
... View more