I have below scenario - Where I am setting vyos in front of my firewall. Vyos will have 2 ISP links
Plus I have VPN tunnel between vyos and R1 which is VTI dynamic tunnels with R1. Now traffic destined to Internet from 192.168.40.x and 192.168.47.x will not be natted on firewall but will be load balanced by Vyos.
However I may need to exclude traffic from source 192.168.47.x and 192.168.4.x to 10.10.11.x since its tunnel traffic.
Am I doing anything wrong here? Will my scenario work in this case?
How do I exclude such traffic then?
I believe I don’t need to exclude the Lan traffic since it will be routed by firewall and I am not natting it on firewall since its a plain forward.
And last but most important, traffic leaving from v1 or v3 going out from v2 and is part of WAN load balancing gets natted/masquerade on v2 or v5 or v8?