If I understand correctly; you have a non-Meraki WiFi system sitting behind a Meraki MX.
You wont be able to do anything on the MX to stop MAC address spoofing being done on a client connected to a WiFi controller connected on another system.
You should consider using some kind of authentication system on your WiFi network, such as WPA2-Enterprise mode, or splash page authentication.
On the MX you can configure a splash page with authentication.
https://documentation.meraki.com/MX/Access_Control_and_Splash_Page/Splash_Page
You could also consider looking at what the customer is accessing. If it is something that is not commonly used you could consider blocking that type of traffic.