I just test It, and I have some considerations:
In beginning I had same issue (My MX is behind a NAT too), so I did a search about FIPS and I found IT:
 
https://documentation.meraki.com/General_Administration/Cross-Platform_Content/Meraki_Device_to_Cloud_Connectivity_-_FIPS 
 

 
Then I changed my IPsec policies configurations like this:
 

 
And guess you ? It worked. I don't like to use 3DES and MD5, but .... OK 😐
 
					
				
			
			
				
	I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.
Please, if this post was useful, leave your kudos and mark it as solved.