I just test It, and I have some considerations:
In beginning I had same issue (My MX is behind a NAT too), so I did a search about FIPS and I found IT:
https://documentation.meraki.com/General_Administration/Cross-Platform_Content/Meraki_Device_to_Cloud_Connectivity_-_FIPS
![alemabrahao_0-1665776316064.png alemabrahao_0-1665776316064.png](https://community.meraki.com/t5/image/serverpage/image-id/26012i8BF70D7EB005A974/image-size/medium?v=v2&px=400)
Then I changed my IPsec policies configurations like this:
![alemabrahao_1-1665776590252.png alemabrahao_1-1665776590252.png](https://community.meraki.com/t5/image/serverpage/image-id/26013iD3E8752F04BE712A/image-size/medium?v=v2&px=400)
And guess you ? It worked. I don't like to use 3DES and MD5, but .... OK 😐
I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.
Please, if this post was useful, leave your kudos and mark it as solved.