Second question is fine, we do this.
MX at site has WAN connected to MPLS and LAN to site network.
MPLS connected to L3 switch at hub, MX has WAN connected in concentrator mode to L3 switch, no LAN connection.
Existing internet firewall retained or replaced by second MX at hub.
If my answer solves your problem please click Accept as Solution so others can benefit from it.