Hi,
I wanted to accomplish pretty much the same thing. I ended up using the built-in Web Proxy with a dedicated VLAN, then marking the outgoing traffic with a routing mark and routing that traffic through the IPSec interface. I created the VLAN only to add an ip address to it which in turn I then use as the src-address for the proxy traffic.
/interface l2tp-client
add connect-to=[vpn server] disabled=no ipsec-secret=[shared secret] name=my_vpn password=[password] use-ipsec=yes user=[username]
/interface vlan
add interface=bridge name=vlan100 vlan-id=100
/ip address
add address=192.168.100.1/24 interface=vlan100 network=192.168.100.0
/ip proxy
set anonymous=yes enabled=yes src-address=192.168.100.1
/ip firewall mangle
add action=mark-routing chain=output new-routing-mark=through_vpn passthrough=yes src-address=192.168.100.1
/ip route
add distance=1 gateway=my_vpn routing-mark=through_vpn
Now you can point your browser to the proxy at [router ip address]:8080 and the traffic will be routed through the vpn. If you want to catch all web traffic without configuring the proxy in your browser you could make the proxy transparent: https://wiki.mikrotik.com/wiki/Manual:IP/Proxy#Transparent_proxy_configuration_example
I hope that helps.
Thanks for the reply, and it worked thank you! Though I did not use L2TP because ProtonVPN doesn’t support it. I’m using IKEv2 and the only thing I changed from your script is:
I didn’t enter this
/interface l2tp-client add connect-to=[vpn server] disabled=no ipsec-secret=[shared secret] name=my_vpn password=[password] use-ipsec=yes user=[username]
For routing, gateway should be the IP of ProtonVPN’s automatic dst-address in the route list already available, so it was in my case 10.1.0.0 and gateway should be 10.1.0.1
/ip route add gateway=10.1.0.1 routing-mark=through_vpn
Thanks again! I didnt know it was doable via web-proxy, been trying to figure out with socks v5.