Hi,
For your topology, I believe it's better to set up the MX as routed mode since you have connected the MX WAN to the public LAN side which should not have access to internal LAN.
Did you change the WAN IP on the MX84 connecting as routed mode and passthrough mode?
If not both modes the client VPN should be able to connect, you may need to check the upstream firewall to make sure the UDP 500 and 4500 been allowed on upstream ISP to your MX WAN IP.
If the client is connected but unable to reach the resource, for passthrough mode, you will need to make sure the WAN GW got the route pointing to the client VPN subnet on MX and is able to route it to your internal network. For routed mode, you will need to set up a new VLAN on MX to connect to your internal switch since the client VPN will set up a separate VLAN on MX and then configure a static route on both MX and your internal switch to allow the VPN subnet to be routed.
If you found this post helpful, please give it kudos. If my answer solved your problem, click "accept as solution" so that others can benefit from it.