Exactly, from the MX-view, it is just a routing-hop to that device that provides the VPN-access to these networks. For the placement of this device, it can be anywhere what is reachable from the MX. I like to place the public interface of the VPN-device in the public network, the internal interface is placed in an MX-DMZ.
If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.