FYI
Previously, I have enabled NAT Mode [Routed Mode / NAT Mode Concentrator / Limited NAT mode] on Meraki vMX for verification purposes,
but the configuration methods and constraints are complex.
* Originally, NAT Mode could not be selected without requesting support.
* Redundancy is limited in NAT Mode because it cannot be a DC-DC Failover topology.
* Since address translation is performed in NAT Mode, the Public Cloud side cannot connect to the Branch side.
This is because the Uplink of vMX is equivalent to WAN1 due to NAT Mode.
The behavior is similar to the general inability to connect from a WAN (Untrust) to a LAN (Trust).
* LAN side settings are special.
LAN setting: Single LAN
MX IP: MX's IP Address
Subnet: Subnet to which vMX belongs
CAUTION: Communication to the specified subnet will be unavailable.
Therefore, vMX should belong to a dedicated subnet for each instance.
Because of this characteristics, either VPN mode setting is acceptable.
A reboot is required for the settings to take effect.
* The Full Tunnel (IPv4 default route) setting is required because the VPN mode setting is practically meaningless.