Thank you for the suggestion! I looked at the linked documentation. This would apply if I were using the VPN to access my GX50 network, but in this case I'm behind my personal GX50 and connecting to my employer's Meraki Client VPN that runs on enterprise hardware (MX84 and MX450 appliances.)
To refresh my memory of the setup routine, I built another network on my GX50 and set it to Guest mode. I came across the following prompt. (Screenshot.) Logically, this prevents guests from seeing internal class A, B, or C networks. I still don't find anywhere that I can control this myself, but what stumps me is that it's affecting the client VPN into another network. It's like the GX50 firewall somehow sees the VPN traffic trying to reach company resources. Ordinarily, I would think that a full tunnel VPN would not be filtered by my own firewall rules. I'll double-check the "Send all traffic over VPN" setting on the work computer, but still scratching my head.