In your place I would create a rule to make sure.
Any devices sitting upstream of an MX will need the following destinations whitelisted so the MX can communicate with the Auto VPN registries:
Port
UDP 9350-9381
IP range for non-China cloud (meraki.com):
209.206.48.0/20
158.115.128.0/19
216.157.128.0/20
IP range for China cloud (meraki.cn):
43.192.139.128/25
43.196.13.128/25
Ports used for IPsec tunneling:
Source UDP port range 32768-61000
Destination UDP port range 32768-61000
I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.
Please, if this post was useful, leave your kudos and mark it as solved.