I am planning a central structure for the internet navigation of the network, where I have the headquarters and the branch.
I would like to force all the internet output of the branch either through the headquarters. Without losing external access to the branch’s RB.
For this I am studying and analyzing which methods and tools I would use.
I wanted your opinion.
For now I think about closing an IPsec VPN between the two units and by mangle rules redirect navigation to the headquarters router.
That way, you would not lose access to RB from the outside for any maintenance emergency, without the need to change the default route and the ipsec vpn as it is perfect and safe.
However, I don’t know if this would be an intelligent use or better management. There may be other more dynamic vpn or routing protocols that would help me in the future to manage more branches.
My main idea is not to manage the branch office firewalls with too many rules, centralizing the navigation in a firewall that would allow me a single point of maintenance.
I thank you in advance for understanding and time for reading and help.
your plan is do-able and might be easier than you think.
lets assume few things:
site A (HQ) and site B (Branch) both has static IP and good internet connection, not just download but also upload bandwidth as well. What is good? depending on your application.
also to do IPSec you need good performance on both routers on each site. what is good? depending on your application. but in general this is not the place you want to cut corners. you safe a penny here, it will cost you a pound in long term.
now the configuration
setup VPN with ipsec, you can search for tutorias for this
Also on site B router:
what you want is setup mangle rule for mark routing, mark winbox traffic first (as Winbox_traffic) , with no pass-through, then mark the rest (as Office_traffic, for example). so that you can add rules in your routing table (this is on the router at site B) for Winbox_traffic to goto your default internet gateway and only office_traffic to go through VPN connection.
what is the upload capacity at HQ? as this will also limit the download capacity for your Branch. assuming it’s more than 10 Mbps.
hardware looks fine to me but other experts feel free to comment.