The hub subnets in this case still need to be advertised to the other MX's which should participate in Auto VPN. The "hub" (spoke) vpn subnets also need to be enabled for the ipsec with non-meraki peers. There are a handful of MX's in the organization which only connect to non-meraki peers in Site A and another site via ipsec tunnel with some identical subnets required between the Auto VPN MX hub and non-meraki ipsec peers. The lack of Auto VPN opt out without also disabling ipsec with non-meraki peers could mean placing MX's in separate organizations is the only solution.
... View more