"You can't add routes via a WAN port. You would need to add a VLAN on the MX and route via that - but you would still need to plug something in a WAN port to give the MX Internet access so it can talk to the cloud."
The problem with this is the fact that this config would require me to have the SD-WAN (VeloCloud) router LAN connected to the Meraki LAN. The VeloCloud (520) is the WAN, as it has all 3 ISP circuits connected to it. I did testing with this design, with mixed results, but without anything in the WAN, it severs cloud management of the Meraki unit. As I do have public static IPs, I could have a second ISP connection to the WAN1 port on the Meraki, but I'd be concerned with firewall effectiveness, as allowing the default ANY/ANY for LAN to LAN traffic would be a risk.
I'm going to test Passthrough mode with a test unit, to confirm functionality and access, but it won't be an exact test.
I'm just hoping that someone will see this conversation and say, "Hey, I did this exact thing with a Meraki firewall and here's how!" I'm also wondering if the use of /24 subnets versus /30 is coming into play.