Meraki helped me with this one. I needed to set the Peer ID as the MX IP-address that it got from the MG. For example 172.31.128.4. And the Peer Endpoint as the MG21 public IP-address. Portforward on the MG21 to the MX. Port 500 UDP and Port 4500 UDP. Then it worked like a charm. 🙂
... View more