Hi Tony, Thanks for the reply. Based on your drawing, I'm trying to see whether its possible to publish a server in the vlan 20 via MX2 using the 1:1Nat. I understand that by doing default route under site to site VPN, everything goes out via MX1. Hence, wondering whether the 1:1NAT policy supersede the default route policy and allow the incoming traffic from web to that server in vlan20 and then have it egress back out via the MX2 WAN. I'm wondering, if Meraki has this feature that allows local internet breakout by source rather than destination, would it works?
... View more