We have just implemented our MX450s at the data center in vpn concentrator mode. However, when you take it out of routed mode, you will require a firewall in front of the Mx to set on the edge for your firewall. We used a couple of firepower’s ASAs, and a Cisco ISR router to take care of the eBGP for the moment. We are waiting on our core switches to come in and should be able to remove the ISR router since the switches can do layer 3. Gonna have a WAN switch and 2 core switches. The fire powers are Natting to the MXs for both wan connections to one interface. Kinda weird to me, cuz I am used to the MXs living on the edge.. tomorrow we are gonna make some adjustments to the BGP to see if we can do full blown BGP now that the MXs are in concentrator mode. I hope this helps. I didn’t really answer your question, however this is the first time I have done this particular setup!! Pretty exciting. I can give you an update after tomorrow if you would like. (I set up a hot spare pair in vpn concentrator mode and named the primary Pete and the secondary Repeat lol 😂).