OK, base on your diagram, it would be best to just have 1 firewall since you do not have a router/L3 switch in your internal network that can do the routing to 2 firewalls.
I believe your preference would be to route everything towards the VPN/ADSL connection?
If you would like to route traffic towards 2 firewalls, ie: one for internet connection and the other for vpn traffic, then you would need to have a router/L3 switch to route the traffic accordingly as follows:
- Traffic towards the internet would have default route/default gateway configured towards the first firewall (for internet connectivity).
- Traffic towards the VPN would have specific routes (remote/HQ LAN subnets) configured to point towards the second firewall (for vpn connectivity).
Hope that helps.