Hi Bruce,
You wrote " a /30 point-to-point link as a transit VLAN on the link, and then another VLAN (normally the native VLAN) which is the management VLAN. The management VLAN then has its Layer 3 interface on the upstream network, whether that’s an MX or something else (e.g. a Cisco router)."
Can you clarify for me: are you saying run two physical links with
1) one physical link carrying a L2 link to the upstream firewall (a Firepower) for the management VLAN;
2) another physical L3 link for the other VLANs?
That would be a good solution, if I could, for instance, use addresses in the 192.168.0.0/24 space for the L3 link and 10.0.0.0/8 for the VLANs. However, I'm constrained by the uplink supplier, which does not allow that, which is why I wanted to use management addresses for the L3 transit as well