How route all internet traffic via S2S IP-SEC vpn from Branch (Sophos-CR25ing) to HQ (Palo Alto)


I am running IP-sec s2s vpn between branch(Sophos- CR25ING, XG v17.5 ) to HQ (Palo Alto-5220), vpn established and working fine.

for better security and filter, we need all traffic should be routed through HQ, how can we achieve this?

I have not found any proper doc

anybody has solution?

Thanks in advance

