You need to add one of the MX LAN IPs that will participate in the VPN, assuming you are going to use 802.1x. If it's Splash Page it needs to be the public IP of the MX.
You can also see in the Radius logs which IP the MX is using to communicate.
I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.
Please, if this post was useful, leave your kudos and mark it as solved.