Latest version of FMC is 6.2.3 and I don’t think ezvpn or hardware clients are supported nor does the Clientless vpn.You might need to consider ipec site to site vpn in hub and spoke topology.I don’t think ezvpn is on the road map either.
I think I saw something on cisco live like below:Receive Packet ->Ingress Interface -> acl permit -> Match XLATE ->Policy Inspection ->NAT IP ->Egress Interface -> L3 Route -> L2 Address -> Transmit PacketAlso Check BRKSEC-2028 on Cisco live