VPN Site to Site problem connect with multi ISP static routes.
I saw several similar problems on this forum, but not exactly like this.
So,
I have: ISP1, ISP2 ,ISP3 links. First two are in sd-wan mode. And I used it for surfing. ISP3 used for business network. My branch office used vpn site to site, and connect over ISP3.
My static route is:
0.0.0.0 -> sd-wan
x.x.x.x -> ISP3
... other routes
x.x.x.x is branch office ip but dynamic change every 24h. So tha vpn to work I have to manually change the address. And this is a problems.
1. I try replace 0.0.0.0 -> sd-wan with 0.0.0.0 -> ISP3 and set SD-WAN in Policy Routes. But I cant add SD-WAN interface in Policy Routing Rules. Only per interface. So that is not solution.
2. I try add ISP3 to member sd-wan, and used sd-wan rules. But If I make this, I cant use independent interface ISP3 to Firewall Policy. Also not solution.
Before Fortigate I used Checkpoint, and that vendor have option to set outgoing interface for vpn, independently of static routes.
Is there anything like Fortigate and what is option for this case?
Thanks
Rade
