"Instead of having the Meraki inline on my MPLS network, could I have the MX LAN interface plugged in to the network (but not inline) would it be possible to create static routes on my core switch that would route to the LAN interface on the Meraki in the event that the remote network was unreachable over MPLS? " You could do this, but I would not recommend it. It would destroy the client tracking and prevent most security features from working. This is because traffic would leave the site via the MX because it is the default gateway, but would return to the client directly since the WAN circuit was in the same VLAN. You want a point to point circuit (via a LAN port) to your WAN circuit. If you are worried about a single point of failure - use two MX units and create a warm spare configuration. This guide talks about the config you are interested in: https://documentation.meraki.com/MX-Z/Deployment_Guides/MPLS_Failover_to_Meraki_Auto_VPN WARNING WARNING WARNING: The MX needs to talk to the Internet via a WAN port as it is cloud controlled. So you will need an Internet circuit at each site plugged into the MX using this approach.
... View more