Because of the cleartext-nature of nearly everything in RADIUS I would always send the traffic through a VPN tunnel. Sadly the Meraki-devices don't support RADIUS-DTLS. That could be natively terminated on the ISE.
For the VPN my first choice would be to integrate an AWS-vMX into autoVPN, but a traditional VPN would also do the job.
If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.