@DavidTa, have a read through what @ww posted, but specifically in regards to your questions…
Q1. No, you’re better of using VPN concentrator mode. Each SSID drops into a separate VLAN on the WAN1 port.
Q2. The subnet you configure on the MX WAN1 port just needs to be a /30. The WAN1 just has to have a IP address that is contactable from the management IP address of the APs.
Q3. You have to configure the DHCP on a downstream device. You can’t run the DHCP services on the MX as it’s a VPN concentrator.
Q4. The gateway for the SSID subnet is downstream from the MX. The link from the MX WAN1 port is a trunk with a VLAN for each of the SSIDs you’re ‘concentrating’.
Hope it makes a little more sense, but feel free to post anymore questions.