Its a limitation of using IKEv1. IKEv1 allows only one SA at a tunnel, secondary SA will not be formed until the primary is deleted. Use IKEv2 to fix the issue. It allows multiple SA at a tunnel and the traffic flows seamlessly. Another Temporary workaround is it use higher prefix on the Meraki. Instead of allowing various 10.20 segment , configure one static route with 10.20.0.0/16 and enable it on VPN.
... View more