Yeah - it looks to me like you should be connecting your Catalyst switch on a LAN port, not a WAN port. Create an appropriate VLAN interface on the MX for that switch and assing the LAN port to that VLAN. You won't need a static route on the MX, unless you're needing to access further subnets beyond the Catalyst switch. As you noted, you will need appropriate routing on the Catalyst, to any subnets which need to be reached via and have their Default Gateway as the MX, on an existing VLAN.