Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Since the question shows the catch-all as *.*, just confirming if you are indeed using the asterisk symbol "*" as catch-all? Also, how does your normal/default policy look for block and allow URLs?
I see API calls to create AP port profiles - https://developer.cisco.com/meraki/api-v1/create-network-wireless-ethernet-ports-profile/ (in case you need it). Strangely enough, not seeing the same for switch port profiles.
Agreeing with PhilipDath's answer. Typically you will be using different tags only if you want any of the PSK, phase-1 or phase-2 settings different for any of the MX68s. If that's the case, you can configure the same peer again and use different set...