Configuring Mikrotik as Firewall

Hello ,
Please i have a scenario which i have mikrotik Hap AC want to configure it as firewall for management bandwidth.

My network is now DHCP server on Domain Controller and i have juniper router connected to the ISP link and doing site to site VPN.

I need to configure the mikrotik as firewall to do the management bandwidth on the employee ,please whats the best scenario to do it ?


Thanks you