What network of interest do they need (the network that needs to communicate)?
If only the LAN network is the first address, if the VPN Client will also need it then it will be both networks.
I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.
Please, if this post was useful, leave your kudos and mark it as solved.