You could deploy in routed mode, if you enable NONAT on the WAN interface connected to your MPLS. You'll be able to route in and out of the MPLS and apply L3 firewall rules to the traffic flow. This is only If you dont mind enabling opt-in "beta" functionality, which NONAT is labelled as. But we've been successfully using it in production as a stop gap until we move everything behind Meraki AutoVPN and NAT. You'll also not get BGP route exchange, and the MPLS will be treated as an external network, so advertising status routes from the hub might be required depending on your topology and needs.
... View more