Just to build on @BlakeRichardson answer.
Content filtering only runs between WAN and LAN interfaces.
Threat protection runs between WAN and LAN interfaces, and also between VLAN interfaces.
https://documentation.meraki.com/MX/Content_Filtering_and_Threat_Protection/Threat_Protection
"Intrusion detection feeds all packets flowing between the LAN and Internet interfaces and in-between VLANs through the SNORT® intrusion detection engine and logs the generated alerts to the Security Report."