Why not just create a vpn tunnel such as wireguard between the two mikrotik routers and thus lan clients at the remote end can access the synology device as required and securely.
Not ikve
Not openvpn
Not ppp variant of anything
not port knocking
not lt2p
Not any other acronymn that doesnt start with the letter W.
You still havent identified equipment at both sides of a potential future connection?
Please draw a network diagram to show equipment connected, and subnet flows going over ports, and ISP connections etc…
IPSec is not bad either. It works best with static public addresses at both sides, but it’s not hard requirement. And if you have right devices, it will be even HW accelerated.