Per your query, yes, the IP should come from behind the MX.
As @DarrenOC noted, a good practice is to have a management VLAN setup. In this case, it doesn't matter that the switch is in front of the MX, you'd carve off one port and put it on (and restrict it to) the management VLAN, connecting it back to your LAN switch so that its communication with the internet/cloud has to pass through the MX and it can grab an IP via DHCP from the management subnet.