Hello @WldWzl ,
When configuring an MX to access a server over VPN, the MX and Z1 use the Appliance LAN IP of the highest-numbered VLAN that is included in the VPN as the source address.
The below document states the above information. Although the document points to radius traffic, the Mx functionality if the same for any traffic sourced from an MX to a remote server (Syslog, Netflow, Radius, AD etc)
Have you tried filtering the traffic for this information?
https://documentation.meraki.com/MX/Other_Topics/MX_and_Z1_Source_IP_for_RADIUS_Authentication
If this was helpful, click the Kudos button below.
If your issue was resolved, we request you to mark the post resolved so other users can benefit in future