Hi there,
I have many clients that are using card machines or Meraki networks and all of them are subject to the PCI/DSS compliance tests (in fact in the UK they get a surcharge each month if the check is not completed or fails).
Firstly I am not sure why you need to do anything other than plug it in and go, it should not need a static IP nor any 1:1 mapping, because the Meraki MX is a stateful firewall the card machine should just connect to the merchant service provider.
Secondly, for the PCI compliance when the company do a port scan looking for open ports, if they find them and report back to you (or your client) as long as you can explain why the ports are open and what measure you have in place to mitigate any breach, they will give you an exception.
An example would be for perhaps the POS till company who may need remote access to the tills for support, you would open the port for VNC but with access only to the specific till IP's - this is what you would then provide this as justification the card company for the VNC port being open.
******* C19 Side note for anyone who is reading this **********
There is a known issue with Ingenico PDQ machines being caused by excessive cleaning using sprays for COVID cleaning, the machines are seeing the liquid dripping behind the keys as an "attack" and locking the machines with an "Alert Irruption Error Message" and the only option is to have the machine replaced, which can take up to 10 days - the solution is only to wipe them with wipes and
CTO & Solutioneer
CMNA, CMNO, ECMS2
SNSA, SNSP
~~If you found this post helpful, please give it kudos. If my answer solved your problem, click "accept as solution" so that others can benefit from it.~~