I am not really sure about your setup at the Hub-location. A L3-diagram could help here ... In general: If your VLANs are configured on the Firewall (MX), then there is nothing else to be done. The traffic automatically flows to the MX and can be sent on to the VPN or the internet. If you have an internal L3-switch that also has routing enabled, this device needs a route pointing to the MX through a transfer-VLAN that is used between the L3-switch and the firewall. This could also be done with the default-route on the L3-switch.
... View more