first mikrotik (back office) connected to internet and have 10 internal devices (pc, laptops, phones, printers).
first mikrotik dial ipsec vpn connection (vpn client) to second mikrotik (main office - vpn server).
what I need now:
all internet traffic
for only 1 internal device in back office (with back office local static IP address)
have to go to open internet via ipsec vpn
and only this one device should to be visible on open internet as MAIN office user,
all other back office devices should go to internet via back office external ip address
is it possible?

http://1c.aliot.ee/files/_temp/ipsec-vpn-internet-2.jpg