Hi @Wooten Best practice would be to place the MXs (concentrators) behind your Corp firewall. They should not be at your internet edge. https://documentation.meraki.com/日本語/Architectures_and_Best_Practices/Cisco_Meraki_Best_Practice_Design/Best_Practice_Design_-_MX_Security_and_SD-WAN/General_MX_Best_Practices if each site already has a L3 core I would go for Passthrough mode.
... View more