Hi and thank you for replying.
I would agree with your suggestion, but if I configure an irb within the VPLS instance as a routing-interface, this would affect only one MX router, the other would not have an irb. If I configured both side with the same irb, how would this work and how would the firewall know which irb he should talk to? I assume both will reply to arp.