If you install a second MX in concentrator mode at the DC plugged into the switch then this can work, we operate an SD-WAN similarly with the exception that the IPVPN at the Head Office (DC) is inside the internet firewall.
If my answer solves your problem please click Accept as Solution so others can benefit from it.