We go with option 1. Separate physical link for your switch management traffic with the L3 interface on your firewall.
then a routed stub connection between the firewall and core with your internal L3 vlan interfaces on your core.
With Option 2 you’ll find that the switches won’t register out to the dashboard.
Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/
I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.