Ideas for S2S with internet centralization

Hi guys.

I would like the help of the experts.

I am planning a central structure for the internet navigation of the network, where I have the headquarters and the branch.

I would like to force all the internet output of the branch either through the headquarters. Without losing external access to the branch’s RB.

For this I am studying and analyzing which methods and tools I would use.

I wanted your opinion.

For now I think about closing an IPsec VPN between the two units and by mangle rules redirect navigation to the headquarters router.

That way, you would not lose access to RB from the outside for any maintenance emergency, without the need to change the default route and the ipsec vpn as it is perfect and safe.

However, I don’t know if this would be an intelligent use or better management. There may be other more dynamic vpn or routing protocols that would help me in the future to manage more branches.

My main idea is not to manage the branch office firewalls with too many rules, centralizing the navigation in a firewall that would allow me a single point of maintenance.

I thank you in advance for understanding and time for reading and help.

Forgive my English.

your plan is do-able and might be easier than you think.
lets assume few things:
site A (HQ) and site B (Branch) both has static IP and good internet connection, not just download but also upload bandwidth as well. What is good? depending on your application.
also to do IPSec you need good performance on both routers on each site. what is good? depending on your application. but in general this is not the place you want to cut corners. you safe a penny here, it will cost you a pound in long term.

now the configuration
setup VPN with ipsec, you can search for tutorias for this

Also on site B router:
what you want is setup mangle rule for mark routing, mark winbox traffic first (as Winbox_traffic) , with no pass-through, then mark the rest (as Office_traffic, for example). so that you can add rules in your routing table (this is on the router at site B) for Winbox_traffic to goto your default internet gateway and only office_traffic to go through VPN connection.

hope this helps you.

where could i learn more about mangle? With examples.

what is the upload capacity at HQ? as this will also limit the download capacity for your Branch. assuming it’s more than 10 Mbps.
hardware looks fine to me but other experts feel free to comment.

as for mangle, you could look at
https://wiki.mikrotik.com/wiki/Per-Traffic_Load_Balancing#Step_3_-_Using_RouterOS.27s_Mangle_Tool_to_mark_specific_traffic

this would be a good starting point.

Speeds are 50/50 and 10/10.

Thank you very much for sharing your knowledge.

I appreciate your time, you took my doubts. Now I must walk alone. Thankful.