By default, an MX will do NAT and hide everything within your internal network (and Reote Access VPN) to its offical IP address on the outside interface.
So, in a nutshell - it could be working right out of the box. Don‘t know anything about your infrastructure though