Passthrough where you connect the WAN port and a LAN port is for placing the MX inline and doing traffic inspection and optional enforcement. If you want to use the MX for SSID tunneling you should be using concentrator mode topology in which you only connect the WAN port. The MX would typically reside in a DMZ network only connected via its WAN port. All traffic entering and exiting on that same WAN interface. I show an example topology in this old thread https://community.meraki.com/t5/Wireless-LAN/Reference-architecture-for-Guest-SSID-tunneling/m-p/151519
... View more