The VPN setting for either 192 subnet would need to be enabled on the spoke (MX64W) to be able to go to the HQs hub which is checked as the default route.
what ever you toggle on for VPN enabled (192 subnet) would be set as access vlan on the MX port for clients.
the downlink to the ms120 would typically have a native vlan for management of the switch plus whatever 192 subnets your clients use.