That only works for Internal User authentication.
For guest user authentication, the requests come from Meraki's cloud.
We have verified this with packet captures and it states this in the documentation I linked to.
Support just responded me and is telling me that we need to open the firewall for all of the subnets and add those subnets as RADIUS clients. This seems like a bit of a security issue. Especially since the rule isn't specific to RADIUS but also applies to NTP so much of those subnets could be referencing just NTP servers and have no need to be allowed inbound.