The MS does not participate in VPN tunnels. It sends packets to its gateway (MX), and the MX handles all VPN encryption/decryption.
The MX encapsulates the packets in an encrypted tunnel after receiving them from the MS.
Tools like MTR on the MS track the route before the packet enters the VPN tunnel, and on the MX, track the route from inside the tunnel.
I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.
Please, if this post was useful, leave your kudos and mark it as solved.