So one device should use the OpenVPN tunnel.
This can be done with routing. There are multiple options to set this up in routing (IP route, Routing, VRF, Rules, Tables) and using routing marks
Menu's in Winbox are on different places for RouterOS 6 and RouterOS 7 !
So it can become confusing.
See
https://help.mikrotik.com/docs/display/ ... cy+Routing
There are multiple solutions, and that alone can make it confusing.
Could be as simple as this for outgoing connections (with a static src IP address 192.168.188.2, and VPN gateway on 192.168..1.1, and VPN interface in the WAN interface list)
/ip firewall nat
add action=masquerade chain=srcnat comment="defconf: masquerade" \
ipsec-policy=out,none out-interface-list=WAN
/ip route
add comment="only for XXX, goes via VPN" distance=1 gateway=192.168.1.1 \
routing-mark=XXX_to_VPN
/ip route rule
add action=lookup-only-in-table dst-address=0.0.0.0/0 src-address=\
192.168.188.2/32 table=XXX_to_VPN