As @CptnCrnch and @DarrenOC said, this should all work fine. I’ve had a good number of customers who run just MRs with Cisco Catalyst switches, and various firewall vendors.
The main thing I’ve found that you can’t do with a MR alone is something akin to a guest anchor. You can configure a guest VLAN easily and use that, but if you’re looking for something like a Cisco guest anchor setup where traffic is tunnelled to a DMZ then you’ll need an MX (in the DMZ) to achieve this.
Personal opinion is that in most cases tunnelling guest traffic is overkill and not required, so you don’t need the MX. But I have had customers who require that extra level of separation between their corporate and guest networks.