You're also loadbalancing
Try:
instead of local address any, specify fixed IP WAN address (eth0 address)
add static /32 route to ipsec peer, using eth0 gateway
You're also loadbalancing
Try:
instead of local address any, specify fixed IP WAN address (eth0 address)
add static /32 route to ipsec peer, using eth0 gateway