First and foremost, generally it’s really easy.
I’ve made it easier by adding CNAME DNS records for the MX Security appliances that host the Client VPN.
On Windows 10 at least, the L2TP VPN does NOT like PAP authentication. The easiest way I’ve found to get around that is a short Powershell
Add-VpnConnection -AllUserConnection -Name "CONNECTION_LABEL" -ServerAddress "IP_OR_FQDN" -TunnelType L2tp -EncryptionLevel Optional -L2tpPsk "PRESHAREDKEY" -RememberCredentials -AuthenticationMethod Pap -Force
Thanks to several google searches and blog entries for that one, especially http://www.ifm.net.nz/cookbooks/meraki-client-vpn.html I’m only including it here as a means of simplifying the search for others.