In this case, this is the expected behavior, the VLAN with the highest ID will be used for this communication. For MX/Z running firmware older than MX 19.1.6, when the MX is configured with Multiple VLANs, the NAS-IP will be the MX IP of the VLAN with the lowest VLAN ID. This is still the case even if that VLAN is not VPN-Enabled. For all MX/Z running MX 19.1.6 and later, the NAS-IP will be the MX IP of the Highest-numbered VLAN ID. MX and Z-series Source IP for RADIUS Authentication - Cisco Meraki Documentation
... View more