Need secure tunnel on existing bridge

Can anyone recommend a simple tunneling method of connecting “NewSite1” to “NewSite2”?
I have a pair of RB450’s just for this purpose.
I tried EOIP a few times using the wiki example but must be missing something somewhere.
The existing wireless is a wds-bridge.
Also I want to protect my Other Stuff. :confused:
temp.jpg

If L3 tunneling is enough, use GRE.

Create GRE interfaces, set keepalive, assign IPs, create routes on both routers.

Adjust firewall/mangle as neccesary.

need secure tunnel on existing bridge…

Eoip, gre, ipip totally unsecured… but gre with ipsec…