That's reassuring. The 1:1 NAT is configured with a public IP in the same subnet. The MX was able to ping the internal hosts.
I have my second attempt in 1.5 days.
I have since made a great discovery. This customer has 95% Meraki infrastructure. Their is an old Cisco UCS chassis switch (in a compute unit). While going through the Meraki events after the event I found lots of spaning tree events where a critical port started flapping.
Now I am aware of that I am going to change things to remove that loop.