Note that Meraki management traffic will NOT flow through a full VPN tunnel. It always go direct.
Also note that the AutoVPN traffic consists of both the tunnel traffic and the orchestration traffic. The tunnel traffic is IPSEC. Tunnel orchestration uses UDP/9350-9381.
https://documentation.meraki.com/MX/Site-to-site_VPN/Meraki_Auto_VPN_-_Configuration_and_Troubleshoo...
"Both Meraki peers must be in communication with the VPN registry in order to get the correct information to form a valid VPN tunnel. If one Meraki device, such as an MX WAN appliance, is able to reach the VPN registry, but the intended peer WAN Appliance is not, the tunnel will not form. A common occurrence of this is when an upstream firewall blocks VPN registry communication on UDP port 9350-9381. This issue is explained in the section VPN Registry Disconnected."