Yes, you can just create a supernet route for 192.168.0.0/16 to point to the MPLS router at HQ, just as you have indicated. The MPLS router would need a route pointing to the MX at HQ for MX connected sites as well. I personally prefer this approach: https://documentation.meraki.com/MX-Z/Site-to-site_VPN/Configuring_Site-to-site_VPN_over_MPLS In this scenario, you use AutoVPN over both MPLS and Internet. In this case, every site needs an MX. In this scenario, your MPLS network only has stub networks connecting to each each at each site, and no longer has any knowledge of your networking (it only sees encrypted traffic). In this scenario there are no statics, and failover is completely automatic. It can also detect failures within the MPLS service provider network, as opposed to just local connectivity issues.
... View more