SpeedFusion VPN Routing issue

Greetings

Hi everyone , I’m new to use PEPlink and have a Speedfusion routing issue need your advice , describe as following:

  1. I have a branch office which establish VPN Connection with HQ , the local Subnet is 10.117.20.0/24.
  2. The Speed fusion VPN is successfully connected to both sites.
  3. AS IS : When the branch LAN (10.117.20.0/24) is going to surfing internet , it is route to VPN Tunnel and PEPlink710 will do NAT go to the ISP line directly. (as the network chart 1 > 2 >5 path)
  4. TO BE: Is there any method or configuration can route Branch LAN packets into HQ Firewall(Palo alto) first? Then go back to another connection between HQ Firewall and PEPlink710, go to the internet via HQ internet line ?
    (as the netwok chart 1 go the the vpn > 2 VPN decrypt >3 route to PA Firewall

4 PA Firewall route to PEPlink710 >5 go to internet via PEPlink again)