Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
In additional to what @Philip D'Ath suggested, you can enable client VPN on those vMX to create a secure tunnel from your internet users (assuming those are your corp users).
@robinson While I don't disagree that Meraki should have full functional vMX in a NAT mode and operate as a stateful firewall in the cloud but I don't see it deployed to terminate SDWAN tunnels, and you would still need to use vMX in the VPN concentr...
I wouldn't consider or use OSPF as the route advertisements are only unidirectional -- From vMX to upstream, and you will need to manually configure the Azure ranges as local subnet in vMX.BGP is 100% what I would go for, and I would consider Azure R...