I have similar question. I have a MX450 acting as a Layer 3 device and DHCP server in addition to a NGFW. Some of the traffic is routed to the MX as its the Layer3 device. On hitting the MX the traffic is routed via a static route back into the LAN to connect to an IPVPN MPLS router connected at Layer 2 to the aggregation switch. So does this traffic going LAN to LAN count towards the firewall flows. Or is it only traffic going from LAN to WAN count as a flow.