Correct, you'd have to use MagicWAN on Cloudflare to be able to connect your MX devices via IPSec.
On the Meraki side of things, this would be handled as Third Party VPN which has quite a lot of pitfalls (currently). So usability / performance wouldn't be the same as using the Umbrella-based solution which is native to the platform.
Apart from that, one could argue which Platform (Cloudflare or Cisco) has better security measures to protect your users and infrastructure. 🙂