The VPN setting for either 192 subnet would need to be enabled on the spoke (MX64W) to be able to go to the HQs hub which is checked as the default route.
what ever you toggle on for VPN enabled (192 subnet) would be set as access vlan on the MX port for clients.
the downlink to the ms120 would typically have a native vlan for management of the switch plus whatever 192 subnets your clients use.
If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.