Not sure if you received your answer or not? Thought I'd respond anyway for posterity.
It's definitely possible to deploy the ASA in a one-armed configuration with the MX appliance. We run several vpn head ends using this design. AnyConnect clients authenticate using Radius, and setting up the port forwarding rules was pretty basic.. We run two ISP's at each site for redundancy, so I typically route VPN traffic through the secondary WAN port to help offload AnyConnect user traffic from the primary internet service.
... View more