Hello, Yes, with Checkpoint FW (R77) we cannot use site to site VPN with dynamic ip, at least with using certificate - which is not feasible with Meraki Z. We will investigate to purchase additional MX as suggested. In resume, if I am not wrong -Goal is deploy Z3 on remote site (home running xDSL and dynamic ip), so we can connect softphone or physical poe phone (as teleworker gateway) -Purchase new MX on HQ and use MX as VPN concentrator -Traffic arriving from MX will be inspected by our Checkpoint FW before accessing the LAN Thank you all for your support Have a great day
... View more