Sometimes you want that also the branch offices send the internet traffic first to the Hub and from there into the internet.
One reason could be that your MXes only have the Enterprise license without any NGFW security. But on the headquarter you have an additional NGFW to protect the traffic. Here it could be useful to use the headquarter as the central internet break out.
If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.