VPN End point setup

Hi Guys.

First post and iv got a question
i have a little hEXLite

i don’t want to use it as a router but rather as a VPN end point…
I have a Client that i cannot control the internet connection on. but can Forward Firewall Ports to an internal IP address.

So My Question is, Can i forward the ports need for a VPN to the hEXLite, and have it Authenticate and let me in on the internal network.
im Assuming i would not plug it in to the WAN port. but if not, which port would it be plugged in to.

Im a newbie on the MikroTik devices but not so much on networking and internet.
(i am having some issues getting used to the interface but i will learn)