We do have a DMZ and have rules from WAN to DMZ, WAN to LAN (but only with reverse proxy) and DMZ to LAN. Ideally we shouldn't have any WAN to LAN, but nobody's perfect!
Unfortunately this isn't with Meraki...
If my answer solves your problem please click Accept as Solution so others can benefit from it.