What we usually do in this case is set the MX64 up with a static IP in on the ISP modem/router subnet and configure port forwarding for it (ports UDP 500 & UDP 4500 for Client VPN). If the customer is running any other local services it may make sense to set the Meraki's IP up as DMZ host on the ISP modem/router. There is an option avaible in beta firmware to disable the NATting on one or both uplinks, although I have never tried that personally.
... View more